Supply Chain Attack
AWS Links the axios npm Hijack Chain to One North Korean Operator
One operator, four poisoned npm packages, over a billion combined weekly downloads. AWS's own report links axios, debug, chalk and typo-crypto to North Korea's Sapphire Sleet at medium confidence — and lays out how the group's tradecraft is shifting into the generative-AI era.