importantSYS.SOURCE: The Hacker News• 2026-07-30T11:35:17+05:30
Amazon Attributes npm Package Hijack (debug, chalk) to North Korea's Sapphire Sleet
Amazon attributes the 2025 npm package hijack of debug and chalk to North Korea's Sapphire Sleet group, citing shared tradecraft across multiple campaigns. The evidence remains thin, with questions about the attribution's validity and technical details like trojanized packages and command-and-control indicators.
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them.
The original Aikido and Wiz reports did not attribute the
*** END OF TRANSMISSION ***