Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has attributed the September 2025 compromise of npm packages debug and chalk, along with subsequent incidents involving typo-crypto and axios, to North Korea’s Sapphire Sleet group. While initial reports attributed these incidents to UNC1069, Amazon’s investigation reveals a pattern of financially motivated campaigns utilizing trojanized packages and post-install hooks. Despite evidence of shared tradecraft and overlapping C2 indicators, a significant gap remains in linking specific incidents to North Korean activity, and the attribution is currently solely based on Amazon's analysis. Recent npm updates have addressed some of the vulnerabilities exploited, but not the underlying maintainer compromise path.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
