The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff ...
Volgens het beveiligingsonderzoek van Amazon werden de aanvallen uitgevoerd door de hackersgroep die in de cybersecuritywereld bekendstaat onder namen als SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff ...
Des pirates nord-coréens seraient à l’origine des compromissions des paquets npm typo-crypto, debug, chalk et axios, selon ...
A DPRK-linked threat actor has been tied to four separate compromises of widely used JavaScript libraries since March 2025, ...
If users are stuck waiting, they don't care which service is slow. Frontend observability helps you see — and fix — what they experience.
Amazon Threat Intelligence has tied a DPRK hacking group to four separate NPM package supply chain attacks, including axios. The company’s security teams have connected the axios, debug, chalk, and ...
Researchers say an unauthenticated vulnerability enables code execution, credential theft, AI memory poisoning, and ...
Amazon links the 2025 debug and chalk npm hijack to Sapphire Sleet with medium confidence, but does not show which evidence ...
New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than ...
The malicious dependency used an npm “postinstall” command, which automatically runs code when a package is installed. Its obfuscated downloader identified the victim’s operating system and deployed a ...
Spread the loveYou’ve poured your heart and soul into a website, meticulously crafting every pixel in Dreamweaver. It looks ...
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs ...