SECURITYCYBERSCOOP
A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon's security researchers revealed that a North Korea-linked hacking group targeted small npm packages like typo-crypto, debug, and chalk as a rehearsal before attacking the widely used axios library. The group used trusted maintainers to publish malicious updates, testing methods that later scaled to larger software. The typo-crypto attack in March 2025 involved a malicious file that activated with a specific numeric input and downloaded platform-specific code.
Mentioned
Related Signal
Adjacent reporting
- North Korean hackers implicated in major supply chain attack
- Axios NPM Package Compromised in Precision Attack
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
- Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware