CTIPilot

Sapphire Sleet

actor · actor:sapphire-sleet

DPRK-linked cluster that Amazon Threat Intelligence assesses with medium confidence (on the basis of command-and-control indicators and TTPs) to be behind the September 2025 compromises of the npm packages debug and chalk and the March 2026 compromise of axios, in each case obtaining publishing access by socially engineering a trusted package maintainer rather than exploiting a registry flaw. Amazon further assesses that a small March 2025 compromise of a package named typo-crypto (into which the actor committed a trojanised file that detonated only on a specific input value and then fetched an operating-system-appropriate second stage) was a testing ground for those later, higher-impact supply-chain operations. The attribution is Amazon's own medium-confidence assessment, independently corroborated on 2026-07-30 when Google's threat-intelligence group separately credited the axios compromise to the cluster it tracks as UNC1069 (already an alias on this record) under its new cryptonym MIDNIGHT NEPTUNE; the alias UNC1069 is sourced to CyberScoop's reporting on Amazon's media roundtable rather than to Amazon's own publication (AWS Security Blog, CyberScoop, 2026-07-29; Google Cloud/GTIG, 2026-07-30).

Aliases: STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, Alluring Pisces, UNC1069, MIDNIGHT NEPTUNE

Coverage timeline
5
first 2026-05-29 → last 2026-08-23
Peak priority
high
2 high · 3 notable
Sources cited
21
14 hosts
Sections touched
3
active-threats, deep-dive, research
Co-occurring entities
6
see Co-occurring entities below
ATT&CK techniques
24
pinned v19.2 · see below
2026-05-295 appearances2026-08-23

ATT&CK techniques

24 techniques observed across 5 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1195Supply Chain Compromise×1

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development Tools×1

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×5

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · ATT&CK page ↗

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1543Create or Modify System Process×1

Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1543.001Create or Modify System Process: Launch Agent×3

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1543.002Create or Modify System Process: Systemd Service×2

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×2

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1543Create or Modify System Process×1

Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1543.001Create or Modify System Process: Launch Agent×3

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1543.002Create or Modify System Process: Systemd Service×2

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×2

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗

Credential Access TA0006

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

Discovery TA0007

T1217Browser Information Discovery×1

Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-06-18/mastra-npm-supply-chain-compromise-easy-day-js · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · ATT&CK page ↗

T1568.002Dynamic Resolution: Domain Generation Algorithms×1

Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions.

Evidence: 2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk · ATT&CK page ↗

Story timeline

  1. 2026-08-23A hijacked crates.io account added the first dependency arrayref has taken in ten years, and that dependency ran a backdoor at compile time; every machine that built an affected project during a ninety-minute window must be treated as compromised
    active-threatsBuild scripts execute before the crate's own code, so `cargo build` was the whole exploit; Wiz ties the infrastructure to two DPRK-linked npm campaigns
  2. 2026-08-04CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats
    researchOverWatch telemetry puts a number on the collapsing patch window, and nation-state actors beat 24 hours on a web-application flaw
  3. 2026-07-30Amazon attributes the axios, debug and chalk npm compromises to a DPRK-linked cluster with medium confidence, and names a small 2025 package compromise as the rehearsal
    researchAmazon Threat Intelligence traces three major npm compromises to one DPRK-linked actor, and describes a payload that only detonates on a specific input
  4. 2026-06-18Mastra npm supply-chain compromise (easy-day-js)
    deep-dive
  5. 2026-05-29Wiz CIRT names JINX-0164, LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
    research

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

overlaps with

Where this entity is cited

  • research3
  • deep-dive1
  • active-threats1

Source distribution

  • attack.mitre.org7 (33%)
  • wiz.io2 (10%)
  • aws.amazon.com1 (5%)
  • bleepingcomputer.com1 (5%)
  • blog.rust-lang.org1 (5%)
  • cloud.google.com1 (5%)
  • crowdstrike.com1 (5%)
  • cyberscoop.com1 (5%)
  • other6 (29%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (21)

Entries about Sapphire Sleet (5)

2026-08-23 · view entry permalink →

HIGHNATOB1

A hijacked crates.io account added the first dependency arrayref has taken in ten years, and that dependency ran a backdoor at compile time; every machine that built an affected project during a ninety-minute window must be treated as compromised

The mechanism here is the whole story, and it is one Rust shares with every ecosystem that lets packages run code at install or build time. Build scripts execute during compilation, ahead of the parent crate's own code, so there is no "use the library carefully" defence: compiling was execution.

On 2026-08-20 an attacker with a compromised crates.io publisher account pushed malicious releases of three widely used crates. Wiz's summary: "On August 20, 2026, malicious versions of three Rust crates were published to crates.io: arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary. Notably, proc-macro1 was the first dependency added to arrayref in its ten-year history" (Wiz Research, 2026-08-20). That last clause is the tell that this was an account takeover rather than a maintainer turning hostile; a crate that has taken no dependency in a decade suddenly taking one, and taking one whose name is a single character away from the ubiquitous proc-macro2. The Rust Security Response Team reached the same conclusion: "We do not believe the author of arrayref to be acting maliciously" (The Rust Project, 2026-08-20), and credits discovery to the research team at Nextron Systems.

The exposure windows were short and are published per crate, "arrayref@0.3.10: published at 2026-08-20T07:15:00Z, deleted at 2026-08-20T08:41:40Z. Online for 86 minutes.", with internment online 90 minutes and append-only-vec 107 minutes, the three publications staggered across about 23 minutes rather than landing together. The team also removed the typosquat dependency and five further attacker-controlled crates, and locked the publisher account.

What ran. The build script reconstructs its command-and-control URL from encoded fragments, disables certificate validation for its own callback, and pulls a platform-specific second stage for 64-bit Linux, Windows and macOS including Apple silicon. The implant beacons over HTTPS, collects host and user details, enumerates installed applications, and queries the SQLite stores Chrome, Brave and Edge use for saved logins. That last point deserves precision, because Wiz corrected itself on it: "Edit: A prior version of this piece mistakenly stated that browser credentials were stolen. The queries only enumerate saved logins, they do not retrieve the encrypted credential material." Enumeration of which sites a developer has credentials for is materially different from taking the credentials, and this entry follows the corrected claim. Persistence is a registry run key on Windows, a launch agent on macOS or a user-scoped systemd service on Linux, and the command set covers reconfiguring the channel, running scripts synchronously or in the background, and terminating. Its resilience feature is worth noting for hunting: "Falls back to a Domain Generation Algorithm if the primary C2 is unreachable, generating 10 algorithmic .com domains every 5 days. Currently, the relevant domains do not appear to be registered." Unregistered today means the sinkhole opportunity is open and the blocking opportunity is not.

Attribution, per claiming vendor. Wiz states "The arrayref infrastructure substantially overlaps with operations attributed to recent North Korean actors", resting it on a beacon endpoint previously seen in the Mastra npm campaign, a shared TLS certificate issuer with Mastra infrastructure, a victim-reported address appearing in Google's analysis of the axios npm compromise, and both campaigns sitting in one hosting provider's address range. The attributions themselves belong to other vendors and should be carried as theirs: Microsoft says of Mastra that "Microsoft assesses with high confidence that this activity is attributable to Sapphire Sleet, a North Korean state actor that primarily targets the financial sector" (Microsoft Security Blog, 2026-06-17), while Google Threat Intelligence Group attributes the axios compromise to UNC1069 (Google Threat Intelligence Group, 2026-03-31). Those two designations resolve to the same cluster this store already tracks, so the overlap is with one actor seen twice rather than two whose relationship is itself unproven, which strengthens the read. Wiz's contribution is the infrastructure linkage, not the attribution.

Scope. Wiz puts arrayref's reach at "over 35% of all environments" and "used in ¾ of all environments where Rust is present"; figures worth carrying with the caveat that the article does not say what population it measures, so they are best read as its own scanning estate rather than a universal claim. Either way the crate is a near-ubiquitous transitive dependency, which is what makes a ninety-minute window consequential.

Detection concepts, telemetry class first. The distinctive signal is in build-time process telemetry: a compiler or package-manager process spawning a network client, or a toolchain process executing a freshly downloaded binary out of a temporary directory. Neither has a legitimate counterpart in most builds, and both are cheap to alert on in CI. Correlate with persistence-creation telemetry in the minutes after a build; a new registry run key, launch agent or user systemd unit appearing on a build host is close to definitive. In egress telemetry, build agents reaching hosts that are not package registries or artefact stores is the broader pattern worth baselining, since CI runners generally have a small and enumerable set of legitimate destinations.

On August 20, 2026, malicious versions of three Rust crates were published to crates.io: arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary. Notably, proc-macro1 was the first dependency added to arrayref in its ten-year history.

Wiz Research 2026-08-20

arrayref@0.3.10: published at 2026-08-20T07:15:00Z, deleted at 2026-08-20T08:41:40Z. Online for 86 minutes.

We do not believe the author of arrayref to be acting maliciously

The Rust Project

any developer workstation or CI runner that built an affected project must be treated as compromised.

The arrayref infrastructure substantially overlaps with operations attributed to recent North Korean actors.

Falls back to a Domain Generation Algorithm if the primary C2 is unreachable, generating 10 algorithmic .com domains every 5 days. Currently, the relevant domains do not appear to be registered.

Wiz Research 2026-08-20

Microsoft assesses with high confidence that this activity is attributable to Sapphire Sleet, a North Korean state actor that primarily targets the financial sector.

Microsoft Security Blog 2026-06-17
threat23 Aug 05:08Zmulti-sourceOpen finding ↗

2026-08-04 · view entry permalink →

NOTABLEexploitedNATOB2

CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats

CrowdStrike's Counter Adversary Operations team published its annual Threat Hunting Report on 2026-08-03, drawing on OverWatch managed-hunting and CrowdStrike Intelligence telemetry from what it describes only as "the past year" (CrowdStrike, 2026-08-03); reporting on the release puts that window at the 12 months to 30 June 2026 (SiliconANGLE, 2026-08-03). Only a few of its findings change a defender's decisions; those are the ones worth carrying.

The one that does most work is the exploitation-velocity measurement: "From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC's release." The named cases go faster still. China-nexus VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of the public disclosure of a critical web-application flaw, and after the React2Shell disclosure OverWatch worked 800+ hunting leads across more than 80 victims in four days. For a Linux local privilege-escalation flaw disclosed on 29 April with a researcher PoC released the same day, OverWatch saw widespread exploit deployment the following day (roughly 94% of first-day events matching public PoC testing behaviour) and for the Belarus-nexus actor UMBRAL BISON, "They uncovered Belarus-nexus activity in just over 20 hours after public disclosure." CrowdStrike's own read is that this pattern predates frontier AI models but that those models are likely to compress the timeline further by accelerating vulnerability discovery and exploit development.

The practical consequence is a prioritisation input rather than a task: for an internet-reachable component, the arrival of a public proof-of-concept is the trigger, and waiting for a KEV listing or the next scheduled maintenance window puts the decision after the exploitation rather than before it. That reframing bites hardest on the exposure classes this constituency runs at the perimeter, the edge appliances, management planes and web applications that need no user interaction to reach.

On the software supply chain, the concentration figure is the useful one: "87% of identified software registry threats in the first half of 2026 involved npm packages", which CrowdStrike attributes to JavaScript's dependency-chain scale and automatic install scripts. The named activity adds tradecraft detail on a cluster this store already tracks under the name Sapphire Sleet, one of whose recorded aliases is CrowdStrike's STARDUST CHOLLIMA: the DPRK-nexus actor used stolen maintainer credentials in March 2026 to compromise the axios npm package and deliver platform-specific variants of its ZshBucket malware, and in June 2026 injected a malicious npm package as a dependency into at least 131 Mastra AI framework packages, which CrowdStrike reads as trusted AI building blocks becoming supply-chain targets. A separate financially motivated actor, ALTERED SPIDER, compromised more than 300 software dependencies in one day, harvested credentials and pivoted into cloud environments.

Three identity and AI observations complete the picture without carrying separate action, because the underlying tradecraft is already covered in this store's operational entries. Vishing intrusions in H1 2026 doubled against H2 2025, with CrowdStrike recording one case in which an eCrime operator moved from account takeover to SaaS data theft in under five minutes. Monthly device-code phishing attempts rose 15x over six months. And on the defender's side of the ledger, "AI agent-triggered detection leads now surface 2.5x more threat leads than manually driven activity", which CrowdStrike frames as making it harder to separate malicious activity from expected AI-driven behaviour, a triage-volume problem rather than an attacker capability gain. One LLMjacking campaign generated nearly 200,000 API requests in two minutes against a hijacked service.

From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release.

They uncovered Belarus-nexus activity in just over 20 hours after public disclosure.

87% of identified software registry threats in the first half of 2026 involved npm packages.

CrowdStrike Counter Adversary Operations 2026-08-03

Builds on: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · 2026-05-09/cve-2026-31431-copy-fail-cisa-kev-deadline-2026-05-15-approa

annual-report04 Aug 04:50Zmulti-sourceOpen finding ↗

2026-07-30 · view entry permalink →

NOTABLENATOB2

Amazon attributes the axios, debug and chalk npm compromises to a DPRK-linked cluster with medium confidence, and names a small 2025 package compromise as the rehearsal

Amazon's threat-intelligence team published an attribution assessment on 2026-07-29 linking three separate npm package compromises to one actor. The load-bearing sentence carries its own hedge, and it should be read with the hedge intact: "based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces" (AWS Security Blog, 2026-07-29). CyberScoop notes that researchers also track this cluster as UNC1069 (CyberScoop, 2026-07-29). Medium confidence is not attribution-by-consensus. Amazon is also precise about which part is new: it states that "while the axios compromise has been publicly attributed to this DPRK-linked threat actor, the typo-crypto, debug, and chalk incidents haven't previously been connected to it" (AWS Security Blog, 2026-07-29). For a defender the actor label changes little, but the tradecraft description below changes something real.

The compromises run from March 2025 to March 2026 and escalate in blast radius: debug and chalk in September 2025, then axios in March 2026, which Amazon describes as one of the most widely used JavaScript libraries at more than 100 million weekly downloads (AWS Security Blog, 2026-07-29). None of them involved breaking the registry. In Amazon's words, "in each case, the threat actor gained access by socially engineering a trusted maintainer of the package, then published a software update containing malicious code" (AWS Security Blog, 2026-07-29), the trust chain held exactly as designed and delivered the malicious version, which is why provenance and signing controls do not help here.

The genuinely new element is the rehearsal. Amazon points at a March 2025 compromise of a package named typo-crypto, into which the actor committed a trojanised file that masqueraded as the unrelated legitimate core-js package, and assesses that "based on the limited number of observed downloads... this campaign was small scale and likely served as a testing ground for the more visible supply chain operations that followed in late 2025 and 2026" (AWS Security Blog, 2026-07-29). That is a patience pattern worth internalising: a package with negligible download counts is not necessarily a failed attack, it may be where the maintainer-social-engineering approach and the payload were refined before being pointed at something with a hundred million weekly installs.

Two mechanics from that rehearsal payload matter for anyone who triages suspicious dependencies. First, detonation was conditional on input rather than on time or environment: the trojanised file executed only when it received a hash input beginning with one specific literal value, and only then downloaded an operating-system-appropriate second stage, with behaviour tailored separately for Windows, macOS and Linux (AWS Security Blog, 2026-07-29). A package like that installs and runs cleanly in any sandbox that does not happen to feed it the trigger value, so "we installed it and nothing happened" is not a clean result. Second, the payload combined file-based persistence with payload rotation and layered obfuscation, base64-encoded text over an XOR cipher under a fixed key (AWS Security Blog, 2026-07-29), so a static scan of the shipped file yields little without unwrapping those layers.

Amazon separately describes a shift in how these operations are structured, observing that attackers increasingly split one malicious workflow across several individually unremarkable packages, and that "this approach is designed to defeat scanners that evaluate packages one by one instead of reasoning about how they interact in a real dependency graph" (AWS Security Blog, 2026-07-29). Amazon frames that as an observation rather than advice, but the implication for a review process is direct: a per-package verdict is the wrong unit of analysis when the malicious behaviour only exists once the pieces are resolved together.

Triage: a benign minified or bundled dependency also carries base64 blobs and unreadable code, so obfuscation alone does not separate the two. The discriminators are behavioural and structural: a code path that stays inert unless a caller supplies a particular argument value, a second-stage fetch whose destination differs by host operating system, and persistence written outside the package's own installation tree. A dependency that reaches the network at all during a build or test run, when its documented function does not require it, is the anomaly worth pulling.

Based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces.

In each case, the threat actor gained access by socially engineering a trusted maintainer of the package, then published a software update containing malicious code.

Based on the limited number of observed downloads, Amazon Threat Intelligence assesses that this campaign was small scale and likely served as a testing ground for the more visible supply chain operations that followed in late 2025 and 2026.

This approach is designed to defeat scanners that evaluate packages one by one instead of reasoning about how they interact in a real dependency graph.

When triggered, it downloads a second-stage payload from a hardcoded C2 server, then executes the payload based on the victim's operating system, with behavior tailored for Windows, macOS, or Linux.

AWS Security Blog 2026-07-29
research30 Jul 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (2)