← All stories
● Covered by 3 sources · 3 reportsMedium impact3 neutral

Amazon Attributes Multiple npm Package Hijacks to North Korea's Sapphire Sleet

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Sapphire Sleet (North Korea) linked to four npm package compromises.
  • Attacks targeted typo-crypto (March 2025), debug/chalk (Sept 2025), and axios (March 2026).
  • Attackers used social engineering to compromise package maintainers.
  • Malicious updates were published, affecting millions of weekly downloads.
  • Amazon assesses the attribution with medium confidence.

Attribution of npm Supply Chain Attacks

Amazon Threat Intelligence has linked several high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to the North Korean threat actor Sapphire Sleet. This group is also known as BlueNoroff and Stardust Chollima. The attribution, made with medium confidence, connects incidents that were previously not publicly linked to the same actor.

Timeline of Compromises

The initial activity began in March 2025 with the trojanization of the typo-crypto package, which Amazon believes served as a testing ground. This escalated in September 2025 with the compromise of the widely used debug and chalk packages. In March 2026, the same operation appeared to compromise axios, one of npm's most popular packages, downloaded over 100 million times each week.

Attack Methodology

Amazon states that all three campaigns began with the same method: socially engineering a trusted maintainer. Attackers gained access to accounts by phishing maintainers through lookalike npm domains. Following access, malicious updates were published, which were then automatically distributed to users of the compromised packages. The debug and chalk compromises alone affected an estimated 10% of cloud environments within two hours.

Impact and Significance

The compromised packages, particularly axios, are embedded in numerous web applications and enterprise services, indicating a broad potential impact. While the axios incident had previously been attributed to North Korean actors by Google (as UNC1069), Amazon's research connects it to earlier package compromises, providing a more comprehensive view of Sapphire Sleet's activities and tradecraft in software supply chain attacks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Amazon has linked several high-profile npm supply chain attacks, including those targeting the debug, chalk, and axios packages, to the North Korean threat actor Sapphire Sleet (BlueNoroff/Stardust Chollima). The attackers gained access by socially engineering package maintainers and published malicious updates, affecting a significant portion of cloud environments. This attribution highlights evolving tactics in software supply chain attacks, including multi-stage payloads and environment-aware malware.

Amazon's security researchers have identified the North Korea-linked group SapphireSleet as responsible for four compromises of popular JavaScript packages on NPM, including axios. These attacks involved socially engineering maintainers to publish malicious updates, impacting organizations that automatically installed the compromised versions.

Amazon Threat Intelligence has attributed the September 2025 hijack of the npm packages debug and chalk, along with other compromises, to North Korea's Sapphire Sleet group. This attribution connects previously separate incidents of crypto theft and package compromise under a single threat actor, highlighting a consistent pattern of social engineering and supply chain attacks.