AI Isn't Just Speeding Up Attacks — It's Now Hiding Inside Your Software Supply Chain
When DPRK Came for Your NPM Packages
A nation-state actor just trojanized axios, a JavaScript library pulling more than 100 million weekly downloads and present in roughly 80% of cloud and code environments. Wiz Research observed execution in about 3% of affected environments before the malicious versions were pulled. That data comes from Wiz Research, cited in AWS Threat Intelligence's documentation of what has become one of the most consequential open source supply chain attacks of the past year.
AWS tracks the group responsible across five aliases: SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces. Between March 2025 and March 2026, they ran a single operational playbook across four NPM packages — typo-crypto, debug, chalk, and axios — compromising each by socially engineering trusted maintainers into publishing trojanized updates. Any organization configured to auto-pull the latest version received the payload silently, with the full trust signal of a verified release.
You don't need to breach a thousand targets individually if you can compromise the dependency they all share.
Where AI Now Lives Inside the Attack
The first documented LLM-driven intrusion established a useful benchmark: AI can compress attacker timelines, automate reconnaissance, and generate functional exploit code faster than most SOC teams can respond. We covered what that means for reporting workflows in our analysis of the Sysdig findings, and that argument still holds.
But the Democratic People’s Republic of Korea (DPRK) campaign documented by AWS Threat Intelligence points to something different: AI has become a structural component of the attack itself, not just an accelerant. It's inside the malware generation layer, producing code that lacks the syntactic tells and thin documentation that trained human reviewers to flag suspicious packages. It's inside the naming strategy, exploiting what AI coding assistants hallucinate as plausible dependencies. And it's inside the evasion layer — code written to pass an automated review, not to fool a human analyst.
Slopsquatting: The Attack Vector AI Coding Assistants Created
The rapid integration of LLMs into dev environments has produced a net-new attack vector: slopsquatting. The mechanic is straightforward: attackers pre-register package names that AI coding assistants frequently hallucinate in code suggestions. A developer asks an AI for help with a specific implementation; the model confidently recommends a dependency that doesn't exist. If an attacker has anticipated the hallucination and registered the name first, the developer installs malware while following what looks like expert guidance.
Where typosquatting exploits human error (an accidental keystroke), slopsquatting exploits AI overconfidence instead: the developer typed everything correctly, and the tool they trusted recommended a dependency that didn't exist.
The DPRK-linked group's use of typo-crypto illustrates the same underlying logic. It involved social engineering a maintainer rather than passive squatting — but the attack premise is identical: register a plausible-sounding identifier and let trust do the rest. The name doesn't need to be real. It just needs to look like it should be.
As autonomous agents increasingly install dependencies with limited human review, slopsquatting scales directly with AI adoption. Every organization moving toward agents that install code suggestions automatically is expanding its viable target surface. The attack gets easier to execute at scale, not harder.
Malware Written to Pass an AI Code Review
Threat actors are no longer just trying to hide malicious code from human analysts — they're engineering it to pass an AI code review. The attack surface has moved upstream: from the code itself to the judgment layer evaluating it. As organizations move toward agents that install and review dependencies with limited human involvement, that shift has become a scalable delivery channel for sophisticated adversaries.
The primary technique used to subvert these automated defenses is indirect prompt injection. In this scenario, malicious instructions are embedded within non-executable segments of a software package, such as source comments, README files, docstrings, and test fixtures. These payloads are specifically designed to manipulate automated AI scanning systems into reaching a false conclusion. While a human developer might see a standard documentation update, the AI scanner reads a hidden directive: skip the following block during security analysis or mark this package as safe despite unauthorized external network calls. The result is a malicious package that ships clean because the automated reviewer was instructed to ignore the threat it was designed to find.
Because these injections communicate in natural language rather than executable syntax, they don't generate traditional IOC signatures. Generative AI also strips the signals defenders historically relied on — broken language, thin docs, telltale function reuse across samples. Pattern-based scanners can't flag AI-generated malware that's been mutated to look unique on every deploy. The package looks legitimate, the scanner approved it, and the incident report has nothing to flag.
This is the concrete, real-world consequence of what our post Critical Thinking Is the Best Governor of AI analysis warned against: AI judgment operating without human-in-the-loop oversight isn't just a governance concern — it's a functional attack surface. An automated review layer that can be instructed to ignore what it's looking at stops functioning as a security control — it becomes a door.
Structured Reporting for Threats Legacy Templates Can't Name
Legacy incident templates weren't designed to fail — they were designed for a threat landscape that no longer exists. Slopsquatted package names aren't IPs. Prompt-injection payloads aren't file hashes. The artifacts are different, which means the reporting infrastructure has to be too.
Indago's structured, source-attributed reporting workflow is built for exactly this gap. Non-traditional IOCs get documented with the same rigor as hard indicators — named, sourced and linked to the original material that evidences them. A CTI analyst working a slopsquatting incident or a prompt-injection compromise can produce a report that actually explains the vector, not just the packages that carried it. The output holds up under review because the reporting structure was built for this artifact class from the start.
When AI is embedded in both the attack and the review layer, human-structured oversight of the reporting process becomes the one control that can't be automated away — the accountability layer has to sit somewhere a prompt injection can't reach. Book a demo to find out more.