Amazon links four poisoned npm packages to North Korean group
UKPulse Health Desk
Amazon researchers have connected four malicious npm packages to a single North Korean crew, identified as Sapphire Sleet.
- Amazon researchers have linked four poisoned npm packages to the Sapphire Sleet group.
- The North Korean crew reportedly used social engineering to compromise maintainers' accounts.
Amazon researchers have attributed four malicious npm packages to a North Korean group known as Sapphire Sleet. The group reportedly employed social engineering tactics to gain control of maintainers' accounts.
Following the compromise, Sapphire Sleet is said to have published malicious updates through these trusted accounts.