HackMyIP
← Back to News
2026-07-31 SecurityWeek

North Korea-Linked Sapphire Sleet Hits NPM Supply Chain, OnTrac and UK Education Breached

Supply ChainAPTData Breach

Amazon Threat Intelligence has attributed recent compromises of the widely used Axios, Debug, and Chalk NPM packages, along with a typo-squatting crypto scheme, to North Korea's Sapphire Sleet group. AWS researchers highlighted the threat actor's preference for high-download packages to maximize downstream impact and noted evolving supply-chain techniques, including fragmented payloads and environment-aware execution logic. The attribution underscores a continuing trend of state-sponsored groups weaponizing the open-source ecosystem for espionage and revenue generation.

In other notable incidents, parcel delivery company OnTrac is notifying customers after attackers accessed its corporate network and exfiltrated files between March 20 and 22. The breach was detected on March 23 and a third-party specialist has been engaged, though no ransomware group has claimed responsibility. Separately, hackers obtained approximately 607,000 records containing phone numbers and email addresses from the UK's Department for Education. Affected individuals can verify exposure using the email breach checker, while the department confirmed that no bank details or sensitive financial information were compromised and that containment was swift.

Huntress also reported a broad credential stuffing campaign targeting SonicWall VPN and firewall accounts beginning July 25, with successful logins confirmed at 30 organizations so far. The activity originates from five DigitalOcean-hosted IP addresses and appears fully automated, with no post-compromise hands-on activity detected. Users and administrators should reset credentials and enable multi-factor authentication immediately, and can audit their exposure with the password checker to identify any reused or compromised secrets.

On the defensive side, Adobe released patches addressing a heap-based buffer overflow in Format Plugins enabling arbitrary code execution, multiple Bridge flaws allowing code execution and privilege escalation, and Priority 1-rated Campaign Classic vulnerabilities permitting arbitrary code execution and file system reads on on-premise deployments. Adobe reports no known in-the-wild exploitation. Meanwhile, OpenAI has open-sourced its Codex Security CLI, a repository scanning tool that tracks findings across runs, verifies fixes, and integrates into CI/CD pipelines. The early release is available via npm and GitHub, with the company inviting community feedback as development continues.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →