The record
Written from the 1 report below. Nothing here is unsourced.
- Amazon Threat Intelligence has attributed the September 2025 hijack of the widely used npm packages debug and chalk to the North Korea-linked group Sapphire Sleet, with medium confidence.
- The company links it to two other npm compromises — a trojanized package called typo-crypto in March 2025 and the March 2026 axios compromise — saying all three began by socially engineering a trusted maintainer.
- Other vendors, including Google and Microsoft, previously attributed the axios compromise to the same cluster, but no other vendor's published research names an actor for the debug, chalk or typo-crypto attacks.
- The report notes Amazon's evidence is thinner than its claim: the attribution came months or years after the incidents, and public registry records for typo-crypto appear inconsistent with the maintainer-compromise pattern Amazon describes.
What to watch next
- Amazon's response on which specific evidence links the debug and chalk compromise, which The Hacker News has requested
- Whether other vendors publish research independently naming an actor for the debug, chalk or typo-crypto compromises
- That typo-crypto@4.3.0 remains published and installable on npm as of July 30, 2026, despite its suspicious record
Coverage1
1 report
English national1
All filed from India
Named North Korea · Axios · chalk · core-js · debug · npm · typo-crypto · Aikido · Amazon · Google · Microsoft · Sapphire Sleet
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
