Skip to content
The Nexus
DossierENTITY

chalk

Coverage of chalk in the Nexus archive.

Earliest in view: May 18 · 22:07 UTCMost recent: Jul 30 · 06:05 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 30 · 06:05 UTCTHE HACKER NEWS
    Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

    Amazon has linked the September 2025 npm package hijack of debug and chalk to North Korea’s Sapphire Sleet. The incident involved a phished maintainer via a lookalike npm domain and a wallet-draining script in 18 packages with over 2 billion weekly downloads. Earlier reports did not attribute the attack to a nation-state.

  • SECURITYJul 29 · 21:09 UTCCYBERSCOOP
    A little-known npm package was North Korea’s warm-up act for the axios hack

    Amazon's security researchers revealed that a North Korea-linked hacking group targeted small npm packages like typo-crypto, debug, and chalk as a rehearsal before attacking the widely used axios library. The group used trusted maintainers to publish malicious updates, testing methods that later scaled to larger software. The typo-crypto attack in March 2025 involved a malicious file that activated with a specific numeric input and downloaded platform-specific code.

  • SECURITYMay 18 · 22:07 UTCTHE REGISTER
    Shai-Hulud copycat worm infects yet another npm package

    A Shai-Hulud copycat worm has been found in another npm package, chalk-tempalte, which is a malicious extension of the popular JavaScript library Chalk. The poisoned package contains a clone of Shai-Hulud, which steals secrets and sends them to a remote server. Four malicious packages have been detected, with a total of 2,678 weekly downloads.

chalk · Dossier · The Nexus