News

Amazon links four poisoned npm packages to one North Korean crew

  • Carly Page--Theregister.com
  • published date: 2026-07-30 13:13:00 UTC

Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts

Amazon has linked the compromises of four npm packages over the past 18 months, saying they were all the work of the same North Korean crew. In research published this week, AWS attributed the activ… [+2810 chars]