Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Summary
Amazon has linked the hijacking of the popular npm packages "debug" and "chalk" to North Korea's Sapphire Sleet threat actor group. This incident, which occurred in September 2025, involved a maintainer being phished, leading to the introduction of a wallet-draining script into at least 18 packages with over 2 billion weekly downloads.
IFF Assessment
This incident highlights a sophisticated supply chain attack by a known threat actor, posing a significant risk to developers and the broader software ecosystem.
Defender Context
This incident is a stark reminder of the risks associated with software supply chain attacks, particularly through popular open-source packages. Defenders should implement rigorous vetting processes for dependencies, monitor for suspicious changes in widely used libraries, and educate developers about phishing tactics targeting code repositories.