Amazon Attributes debug/chalk npm Hijack to North Korea's Sapphire Sleet

Two more package hijacks, one DPRK attribution — Amazon's callout lands this week.

Share
Flat white line-art of two package boxes linked by a line to a location pin, on a teal background — Amazon npm debug and chalk Sapphire Sleet attribution.

Key Takeaways

  • Amazon on July 29, 2026 published research attributing the recent hijack of the widely used debug and chalk npm packages to a North-Korea-linked cluster it tracks as Sapphire Sleet, and assessed with medium confidence that the same operator was also behind the earlier compromise of axios — placing four poisoned npm packages under one threat actor's timeline.
  • Amazon's threat-intelligence team frames the activity as a patient, financially motivated developer-targeting operation that reportedly worked through maintainer trust rather than a single smash-and-grab, with a little-known package, typo-crypto, reportedly serving as a March 2025 rehearsal roughly a year before the axios hijack.
  • For defenders the disclosure is an attribution-and-continuity story, not a new exploit: it consolidates several 2026 npm incidents under one North-Korea-linked cluster, and The CyberSignal reports the payload specifics, the downstream projects affected, and any coordinated npm or GitHub advisories as still-open questions rather than settled facts.

Amazon's threat-intelligence team ties the debug and chalk npm hijacks to North Korea's Sapphire Sleet — and, reportedly, to the same operator behind the earlier axios compromise.

SEATTLE, WASHINGTON — Amazon on July 29, 2026 published research attributing the recent hijack of the debug and chalk npm packages — two of the JavaScript ecosystem's most widely used libraries — to a North-Korea-linked threat cluster it and others track as Sapphire Sleet, assessing the link with medium confidence. The finding, relayed the same day by The Hacker News and The Record and followed on July 30 by CyberScoop, reframes what had been an anonymous package hijack into one thread of a documented, state-aligned operation.

The disclosure lands as a continuation of the earlier axios npm-hijack thread rather than a standalone event. As reported by The Hacker News and CyberScoop, Amazon assesses that the operator behind debug and chalk was also behind the compromise of axios — one of npm's most-downloaded HTTP clients — and that a little-known package, typo-crypto, reportedly served as a warm-up a year earlier. This piece summarizes what Amazon attributed and what remains unconfirmed, and it deliberately does not reproduce the packages' payload mechanics.

At a Glance
FieldDetails
WhatAmazon attribution of the debug and chalk npm-package hijacks
Attributed byAmazon's threat-intelligence team, per reporting
ActorNorth Korea's Sapphire Sleet (aliases include BlueNoroff, Stardust Chollima)
ConfidenceMedium, per Amazon's stated assessment
Linked packagestypo-crypto (reported rehearsal), debug and chalk, and axios
Disclosure dateJuly 29, 2026; follow-up reporting July 30
Downstream impactSpecific affected projects not fully established — open question
Related coverageCyberSignal npm supply-chain and Sapphire Sleet attribution reporting

What Amazon Disclosed

According to reporting from The Hacker News and The Record, Amazon's threat-intelligence team published an analysis attributing the hijack of the debug and chalk npm packages to Sapphire Sleet, a North-Korea-linked cluster, and assessed with medium confidence that the same operator carried out the earlier axios compromise. Amazon's account, as relayed in the reporting reviewed and in the company's own security blog, describes a patient operation that reportedly worked by earning the trust of package maintainers and publishing poisoned updates from accounts developers already relied on — a maintainer-trust route rather than a direct break-in.

The CyberSignal is deliberately not reproducing the packages' payload mechanics. The defender-relevant facts are the attribution itself, the named actor, Amazon's stated confidence level, and the way the disclosure stitches several 2026 npm incidents into one operator's timeline. This is a vendor attribution — a probabilistic assessment built on overlaps in infrastructure and behavior — not a government indictment or a sanctions action, and Amazon was explicit that it holds the debug and chalk link at medium confidence.

What Sapphire Sleet Is

Sapphire Sleet is one vendor's name for a financially motivated, North-Korea-linked threat cluster with a documented history of targeting developers and cryptocurrency holders. Other researchers track overlapping or equivalent activity under aliases including BlueNoroff and Stardust Chollima; different vendors draw cluster boundaries differently, so the label is best read as a mapping onto a broader body of DPRK-linked activity rather than a settled, universal taxonomy. The CyberSignal has covered the cluster before, when Microsoft attributed a separate npm supply-chain compromise to Sapphire Sleet earlier this year.

The cluster's through-line, across the reporting, is money: reaching developers as a route to the credentials and crypto assets they can access. That framing matters because it tells defenders how to weigh a single npm incident — as one move in a sustained, resourced campaign rather than an opportunistic one-off. It also explains why Amazon's disclosure reads as continuity: the same motive and the same target surface recur across the packages named.

The npm Supply-Chain-Hijack Timeline

What makes the Amazon disclosure notable is less any single package than the timeline it assembles. Per CyberScoop, the operator reportedly began with typo-crypto, a little-known package trojanized in March 2025 that Amazon describes as a rehearsal — a way to test methods without drawing attention on a bigger stage. Reporting then places the compromise of the far more widely used debug and chalk packages in September 2025, and the compromise of axios, one of npm's most-downloaded HTTP clients, in March 2026.

The axios link is where this disclosure connects to prior coverage. The CyberSignal previously reported ESET's account tying the axios compromise to the Lazarus umbrella, and Microsoft's separate attribution of a distinct npm compromise to Sapphire Sleet. Amazon's assessment now reportedly places typo-crypto, debug, chalk, and axios under one operator. Readers should note the caveat that different vendors use different cluster names and confidence levels, so the exact boundary between "Lazarus," "Sapphire Sleet," and adjacent labels remains a matter of each vendor's mapping rather than a fixed line.

What Node.js Operators Should Verify

For teams that consume npm, the practical work is inventory and hygiene rather than novel detection. The starting question is whether any developer workstation, build agent, or continuous-integration pipeline installed an affected version of debug, chalk, or axios during the relevant exposure windows — because the risk from a poisoned package is driven by what a build agent installed, not only by what an application imports at runtime.

Where an affected version was pulled, standard supply-chain response applies: pin known-good releases, treat potentially exposed developer and build hosts as suspect, and prioritize rotating any credentials, tokens, or keys those systems could have handled. Longer term, the disclosure strengthens the case for durable controls The CyberSignal has tracked across registries — scoping which build systems can reach the public internet, scrutinizing install-time scripts, and treating maintainer-account takeover as a foreseeable risk rather than an outlier, a pattern also seen in Microsoft's disclosure of a dependency-confusion campaign across dozens of npm packages.

Open Questions

Several specifics are unresolved in the reporting reviewed, and The CyberSignal is not filling them in. The payload each package delivered, the specific downstream projects affected, and whether npm or GitHub have published coordinated advisories are not established here. It is also not confirmed whether Amazon's medium-confidence assessment will be independently corroborated by other vendors, or whether the axios attribution — which other vendors have tied to the broader Lazarus umbrella — will converge on the Sapphire Sleet label.

What is established is the core of Amazon's claim: that the debug and chalk hijacks were, in the company's medium-confidence assessment, the work of a North-Korea-linked cluster also reportedly behind axios, with typo-crypto as an earlier rehearsal. As with any single-vendor attribution — and as registries from npm to RubyGems have shown when they weigh coordinated responses — the picture will sharpen as additional vendors, registry operators, or government bodies weigh in.


The CyberSignal Analysis

The reported facts above come from Amazon's disclosure and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts, and all preserve Amazon's own medium-confidence, single-vendor framing.

Signal 01 — Attribution Consolidates a Thread, It Doesn't Reopen It

The value of Amazon's disclosure is consolidation: it gathers typo-crypto, debug, chalk, and axios into one operator's timeline rather than handing defenders a new exploit to chase. Our reading is that the remediation checklist for a poisoned package does not change because a nation-state name is attached — teams still audit dependency trees, pin good versions, and rotate exposed secrets — but the urgency and the time horizon do. A compromise attributed to a persistent, state-aligned cluster is better modeled as one move in an ongoing campaign than a closed incident.

The practical use of the Sapphire Sleet label, for most organizations, is triage weighting — how long to keep watching, and how much to invest in prevention — not a novel indicator to hunt. The mechanics of each compromise, which we are not reproducing, remain the operative detail for cleanup; the attribution is what tells a security team how seriously to keep taking the ecosystem it depends on.

Signal 02 — The Patient, Maintainer-Trust Route Is the Real Lesson

The detail most worth internalizing is the tradecraft Amazon describes: reportedly earning maintainers' trust and publishing from accounts developers already relied on, rather than forcing entry. Our assessment is that this patient route is what makes registry compromise hard to catch, because the poisoned update arrives through exactly the trust relationship the open-source ecosystem runs on. The typo-crypto rehearsal, roughly a year before axios, underscores that this is planning, not opportunism.

For defenders, that argues for controls that assume trusted accounts can be turned — install-time script scrutiny, provenance checking, and treating maintainer-account takeover as a design assumption rather than an edge case. The lesson is not that one more package went bad, but that a resourced actor is willing to invest a year of quiet preparation to reach developers at scale.

Signal 03 — A Medium-Confidence Vendor Call Is Not a Consensus

Amazon's judgment is explicitly medium confidence, and the axios thread has been tied by other vendors to the broader Lazarus umbrella under different names. Our reading is that this hedging is a feature of the disclosure, not a weakness: vendor attribution is probabilistic, cluster boundaries differ between researchers, and treating a single company's mapping as settled fact overstates what any one vendor can establish about a state operation.

The forward-looking watch item is convergence — whether other vendors, npm, GitHub, or a government body corroborate the call, and whether the various labels settle onto a shared picture. Until then, the Sapphire Sleet attribution is best carried in internal reporting as actionable for prioritization but explicitly single-source and medium-confidence, with the alias caveats preserved.


Sources

TypeSource
PrimaryAmazon Security Blog — Amazon identifies North Korean hacker group behind open-source supply chain attacks
ReportingThe Hacker News — Amazon Links Debug and Chalk npm Hijack to North Korea's Sapphire Sleet
ReportingCyberScoop — A little-known npm package was North Korea's warm-up act for the axios hack
ReportingThe Record — North Korean hackers behind major open-source supply chain attacks, Amazon says
RelatedThe CyberSignal — Microsoft Attributes Mastra npm Compromise to Sapphire Sleet
RelatedThe CyberSignal — ESET APT Report: Lazarus Compromises axios npm
RelatedThe CyberSignal — Microsoft Names 33 Malicious npm Packages in a Dependency-Confusion Campaign
RelatedThe CyberSignal — RubyGems Suspends New Signups After Major Malicious Attack