Published July 29, 2026 ยท Added August 4, 2026

North Korea Behind Slew of JavaScript Supply-Chain Hacks

HealthcareInfoSecurity reports that Amazon Web Services linked compromises of open-source JavaScript packages including Axios, Debug, Chalk, and Typo-Crypto to the North Korean threat actor tracked as Sapphire Sleet or Stardust Chollima, underscoring continuing npm and PyPI supply-chain risk.

HealthcareInfoSecurity reports that Amazon Web Services linked compromises of open-source JavaScript packages including Axios, Debug, Chalk, and Typo-Crypto to the North Korean threat actor tracked as Sapphire Sleet or Stardust Chollima, underscoring continuing npm and PyPI supply-chain risk.

Read the original story.

Source: Healthcareinfosecurity