0
Deep & Emerging Tech·July 30, 2026·1 min read

Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet

Share

Four compromised npm packages over 18 months—via social engineering of maintainers—reinforces that your software supply chain risk now includes upstream humans, not just code. Lock down dependency policies, pin and mirror critical packages, and assume popular OSS components are active targets for state-linked actors.