SECURITYTHE HACKER NEWS
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has linked the September 2025 npm package hijack of debug and chalk to North Korea’s Sapphire Sleet. The incident involved a phished maintainer via a lookalike npm domain and a wallet-draining script in 18 packages with over 2 billion weekly downloads. Earlier reports did not attribute the attack to a nation-state.
Related Signal
Adjacent reporting
- A little-known npm package was North Korea’s warm-up act for the axios hack
- Microsoft links Mastra AI supply chain attack to North Korean hackers
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
- NPM packages from RedHat have been compromised