Thursday, August 6, 2026 Latest Amazon Funds Akrites Initiative After Sapphire Sleet NPM Attacks Our standards
Technology

Amazon Funds Akrites Initiative After Sapphire Sleet NPM Attacks

Global open-source supply chains faced coordinated breaches in 2025 and 2026 as North Korean threat actors socially engineered package maintainers to poison widely used Node Package Manager libraries, prompting Amazon to link the campaigns and invest $12.5M in the Akrites initiative to protect critical software infrastructure.

Security researchers and cloud computing giants are confronting a sophisticated, long-term open-source software campaign targeting the digital supply chain. Amazon connected multiple high-profile compromises within the Node Package Manager ecosystem to the Sapphire Sleet threat actor, also recognized as BlueNoroff and Stardust Chollima.

Attackers then escalated their efforts in September 2025 by compromising the widely used debug and chalk libraries, which managed to reach an estimated 10% of cloud environments within two hours of publication. By March 2026, the targeting shifted to axios, one of the most popular npm packages boasting over 100 million weekly downloads.

Social Engineering Maintainers and Weaponizing AI

The mechanics of the npm intrusions relied heavily on human manipulation rather than traditional zero-day exploits. The attacker gained access by socially engineering package maintainers to publish malicious updates that automatically rolled out to downstream developers. Investigators assigned a medium confidence level to the Sapphire Sleet attribution, citing shared tactics, techniques, and procedures, overlapping command-and-control infrastructure, and consistent operational patterns.

Amazon Funds Akrites Initiative After Sapphire Sleet NPM Attacks
Photo: cointelegraph.com

Beyond standard social engineering, the campaign highlighted emerging threats driven by artificial intelligence. Threat actors spent months building credibility by maintaining legitimate code or contributing to projects before injecting malicious code. They split payloads across benign packages, relied on external scripts for weaponization, and utilized environment-aware malware that delayed execution unless real developer or production sandboxes were detected. Attackers also exploited slopsquatting by registering package names hallucinated by AI coding assistants, betting that developers or autonomous coding agents would automatically install them.

Parallel Crypto Attacks and State-Level Revenue Streams

While software supply chains faced automated and AI-assisted infiltration, decentralized finance platforms absorbed parallel shocks from targeted phishing operations. Humanity Protocol suffered a $36 million theft of Humanity (H) tokens after a compromised employee laptop allowed attackers to gain full remote access as detailed in Quantstamp incident response findings.

Amazon Funds Akrites Initiative After Sapphire Sleet NPM Attacks
Photo: dailyhodl.com

Blockchain security firm Quantstamp identified a malicious attachment disguised as a token lockup schedule update from South Korean cryptocurrency exchange Bithumb. The malware was signed with a South Korean Hancom digital certificate—a signature pattern described by security analysts as characteristic of DPRK intrusions—which enabled attackers to copy project director Chong Yee Wai’s MetaMask wallet credentials and private keys.

These incidents fit into a much larger, industrialized financial apparatus. Over the past decade, North Korea-linked actors stole an estimated $6.75 billion in cryptocurrency across 263 documented incidents, according to a report from CertiK. Those figures included at least $578 million tied to North Korean threat actors out of $634 million stolen in crypto exploits during April alone.

Internal Financial Fallout and Industry Defense Responses

“The ring converted stolen state trade funds into cryptocurrency and smuggled large amounts of foreign currency in border regions, the source said… The breach struck at the core of North Korea’s financial system. It came from within, carried out by the country’s own IT workforce.”

North Korea-Linked Hackers Breach Axios Software Update | WION Dispatch
Anonymous source, via Daily NK

News of the internal scandal generated widespread alarm among high-ranking military and academic circles. Meanwhile, state media outlets continued to deny involvement in global cybercrime, with a Foreign Ministry spokesperson featured in the Korean Central News Agency dismissing allegations as a non-existent ‘cyber threat’ pushed by the United States.

In response to the expanding scope of supply-chain compromises, Amazon deployed a multi-faceted defense strategy by investing $12.5M in the Akrites initiative, which collaborates with OpenSSF and industry partners to protect critical open-source software against AI-enabled attacks.

Accuracy matters. See something that needs attention? Read our corrections policy or contact the newsroom.

Technology Editor

Maya Serrano

Maya Serrano is the editorial identity for TellingPointy's Technology desk, covering artificial intelligence, platforms, software, hardware, cybersecurity, and digital policy. Serrano's work translates complex systems without sanding away the important details. Her desk asks who controls a technology, what data and incentives power it, where the real limits sit, and how a product or policy changes the balance among users, companies, governments, and the wider public.