Carly Page / The Register:
Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet — Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts
Posted from: this blog via Microsoft Power Automate.