Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet

Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts