Threat Actor Unknown origin
STARDUST CHOLLIMA
Also known as: Sapphire Sleet
Open-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public reported as part of the “Lazarus Group”), because Hermes was executed on a host during the SWIFT compromise of FEIB in October 2017.
Indicators of Compromise 9
MITRE ATT&CK TTPs 11
T1027 T1029 T1053.005 T1059 T1059.001 T1071.001 T1105 T1195.002 T1566 T1583 T1610
Obfuscated Files or Information
Defense Evasion
Scheduled Transfer
Exfiltration
Scheduled Task
Execution
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
Ingress Tool Transfer
Command And Control
Compromise Software Supply Chain
Initial Access
Phishing
Initial Access
Acquire Infrastructure
Resource Development
Deploy Container
Defense Evasion
Source Articles
Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog
Amazon Threat Intelligence has identified a DPRK-linked threat actor behind multiple supply chain attacks on popular NPM packages including axios, debug, chalk, and typo-crypto. The actor used social engineering to gain access to maintainer accounts and published trojanized updates containing malicious code. These attacks leveraged post-install hooks, multi-stage payloads, and C2 infrastructure to deliver malware across thousands of downstream environments. The same actor is assessed to have tested their tradecraft in a smaller campaign via the typo-crypto package before escalating to higher-impact compromises. The group uses sophisticated evasion techniques including code obfuscation, environment detection to avoid sandboxes, and generative AI to produce convincing malicious packages.
static-urls
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon has linked multiple npm supply-chain attacks to the North Korean threat actor Sapphire Sleet (also known as BlueNoroff and Stardust Chollima) with medium confidence. The attacks began in March 2025 with the compromise of the typo-crypto package, followed by the trojanization of widely used packages debug and chalk in September 2025, impacting an estimated 10% of cloud environments within two hours. In March 2026, the axios library—used by over 100 million developers weekly—was targeted, with malicious updates distributed after attackers socially engineered maintainers to gain access. The campaign used sophisticated tactics including delayed execution in real environments, multi-stage payloads, and 'slopsquatting' of AI-hallucinated package names to expand reach.
bleeping-computer ·4w ago