Threat Intelligence / Actor / Sapphire Sleet (BlueNoroff
Sapphire Sleet (BlueNoroff
As of 2026-08-25, Sapphire Sleet (BlueNoroff is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 16 threats spanning supply chain. Also known as UNC1069), Sapphire Sleet, alluring pisces, bluenoroff.
Also known as: Sapphire Sleet (BlueNoroff, UNC1069, UNC1069), Sapphire Sleet, alluring pisces, bluenoroff, cageychameleon, copernicium, cryptocore, genie spider, stardust chollima, APT38
Tracked threats
- Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform infostealer backdoor at compile time — CRITICAL
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor — CRITICAL
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet) — CRITICAL
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack — CRITICAL
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages — HIGH
- Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked Maintainer Account — CRITICAL
- North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop — HIGH
- Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT Dropper — CRITICAL
- Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple Certificate Rotation — DPRK UNC1069 / Sapphire Sleet WAVESHAPER.V2 — CRITICAL
- Axios npm Supply Chain Compromise — WAVESHAPER.V2 Cross-Platform RAT Deployment by UNC1069/Sapphire Sleet (DPRK) — CRITICAL
- Axios npm Supply Chain Compromise by Sapphire Sleet (DPRK) — Cross-Platform RAT via Phantom Dependency — CRITICAL
- UNC1069 Compromises Axios NPM Package in Supply Chain Attack Deploying WAVESHAPER.V2 Cross-Platform Backdoor — CRITICAL
- North Korea (UNC1069) Supply Chain Compromise of Axios NPM Package via Backdoored plain-crypto-js Dependency — CRITICAL
- Axios NPM Supply Chain Compromise — Cross-Platform RAT via Malicious Transitive Dependency (plain-crypto-js) — CRITICAL
- Axios npm Supply Chain Attack: Cross-Platform RAT Delivery via Compromised Maintainer Credentials (GHSA-fw8c-xr5c-95f9) — CRITICAL
- Axios npm Supply Chain Attack via Malicious plain-crypto-js Dependency (Cross-Platform RAT Dropper) — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →