Amazon Threat Intelligence has linked four npm supply-chain attacks conducted between March 2025 and March 2026 to Sapphire Sleet, a threat actor associated with North Korea. Based on that evidence, Amazon Threat Intelligence attributed the campaign with medium confidence to Sapphire Sleet, a threat actor associated with North Korea. Trust became the attack surfaceUnlike many software supply-chain attacks, Amazon says this campaign did not begin with attackers discovering and exploiting a previously unknown flaw in npm packages. AdvertisementHow organizations can reduce open-source supply-chain riskAmazon’s report reflects a broader challenge facing enterprises. Amazon’s findings show that software supply-chain security depends not only on finding vulnerabilities in code, but also on protecting the identities trusted to distribute it.