AUTO-UPDATED

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon Threat Intelligence has attributed the September 2025 hijacking of popular npm packages debug and chalk to North Korean state-sponsored actors, citing patterns in malicious software development.

Key Points

  • Amazon links the debug and chalk compromises to the same group behind the March 2026 axios attack, identifying them as North Korean operatives.
  • The campaign involved socially engineering maintainers to push malicious updates into packages that collectively see over 2 billion weekly downloads.
  • Analysts identified a 2025 test run involving a trojanized package called typo-crypto, which used obfuscated code and hardcoded command-and-control servers.
  • While Amazon claims the attacks share consistent tradecraft, other security firms like Aikido note that the technical execution methods varied significantly between incidents.
  • Despite recent security updates, npm still lacks comprehensive defenses against the social engineering tactics used to compromise legitimate developer accounts.

Why it Matters

This attribution highlights the persistent threat North Korean actors pose to the global software supply chain by targeting widely used open-source dependencies. As these attacks evolve, they demonstrate that even high-traffic packages remain vulnerable to sophisticated social engineering, necessitating more robust verification processes for software maintainers.
Internet Published by info@thehackernews.com (The Hacker News)
Read original