Security · 1h ago
Amazon Links npm Hijack of Debug and Chalk to North Korea
Amazon has attributed the September 2025 hijack of npm packages debug and chalk to North Korea's Sapphire Sleet group. The attack, previously seen as crypto theft, involved a phishing campaign that compromised packages with over 2 billion weekly downloads. The incident remained unattributed for ten months until Amazon's investigation.
Meridian48 take
The attribution adds a state-sponsored dimension to what was initially dismissed as a routine supply-chain attack, underscoring how long sophisticated threats can fly under the radar.
Read the full reporting
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet →
The Hacker News
npm-supply-chainnorth-korea