Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon Threat Intelligence says the September 2025 hijack of debug and chalk was linked to a North Korean group, connecting it to earlier activity involving typo-crypto and the March 2026 axios compromise. The report points to shared tradecraft, trojanized packages, and overlapping command-and-control infrastructure, but the evidence publicly shared remains incomplete. #debug #chalk #typo-crypto #axios #UNC1069 #SapphireSleet #STARDUSTCHOLLIMA #BlueNoroff #AlluringPisces #CageyChameleon #CryptoCore

Keypoints

  • Amazon tied the debug and chalk hijack to North Korea with medium confidence.
  • The same actor group was linked to the March 2026 axios compromise.
  • Amazon says typo-crypto may have been a test run for later attacks.
  • Google and Microsoft attributed axios to UNC1069 and Sapphire Sleet.
  • npm v12 and malware scanning reduce risk, but do not stop maintainer compromise.

Read More: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html