Amazon links the debug, chalk, axios, and typo-crypto npm package compromises to North Korea's Sapphire Sleet

Amazon says a series of major npm package compromises that hit widely used JavaScript libraries were carried out by North Korea-linked hackers, putting downstream software users and cloud environments at risk. The company attributes the typo-crypto compromise in March 2025, the debug and chalk attacks in September 2025, and the axios compromise in March 2026 to Sapphire Sleet, also known as BlueNoroff and Stardust Chollima, saying the actor socially engineered maintainers and published malicious package updates through legitimate accounts.
Why it matters: Developers and organizations that automatically pulled affected npm updates may have installed attacker code through trusted software components. This is a supply-chain risk with broad downstream reach, so defenders should review exposure to those packages, audit build pipelines, and tighten maintainer account protections and dependency controls.

Sources

AI is 'both the weapon and the target' in latest wave of cyberattacks
2026.08.03 73% relevant
This article adds CrowdStrike's assessment that the March Axios supply-chain attack was likely conducted by Lazarus offshoot Stardust Chollima, also known as Sapphire Sleet, and places it in a broader pattern of AI-enabled and supply-chain attacks.
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
SecurityWeek News 2026.07.31 98% relevant
This is a direct update on the same event, adding Amazon Threat Intelligence's attribution details and noting Sapphire Sleet's use of fragmented payloads, environment-aware malware, and focus on high-download packages for downstream impact.
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Bill Toulas 2026.07.30 100% relevant
The article establishes a concrete new umbrella story by tying several previously separate npm compromises to the same North Korean actor and campaign tradecraft, rather than reporting just one isolated package incident.
← Back to all stories