Amazon Connects npm Hacks to Threat Actor Known as 'Sapphire Sleet' A slew of attacks against open-source libraries trace back to a financially-motivated North Korean nation-state threat actor, analysis from Amazon Web Services set for publication Thursday finds. Amazon makes the assessment of North Korean responsibility with high confidence.