Connect with us

Cybersecurity

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Published

on

Amazon Threat Intelligence has linked the 2025 hijacking of popular npm packages debug and chalk to a North Korean cyber threat group, marking a major shift in the understanding of an incident initially viewed as a cryptocurrency theft campaign.

The attacks, which affected widely used JavaScript packages with billions of weekly downloads combined, were previously investigated as a software supply chain compromise involving a phishing operation against an npm maintainer. Researchers now say the campaign may have been connected to a broader North Korean operation targeting cryptocurrency assets and developer ecosystems.

From Crypto Theft Incident to State-Linked Attribution

The original investigations by cybersecurity firms Aikido and Wiz did not publicly attribute the attack to North Korea. Amazon Threat Intelligence later assessed with medium confidence that the group responsible for the debug and chalk compromises was connected to the same threat actor behind the March 2026 compromise of the popular npm package axios.

According to Amazon, the attackers followed a consistent method across multiple campaigns: gaining access through social engineering, compromising trusted package maintainers, and publishing malicious updates that could reach large numbers of developers.

Amazon identified similarities between several incidents, including the use of trojanized packages, command-and-control infrastructure, and reused attack techniques.

Malicious Code Targeted Cryptocurrency Transactions

The compromised packages contained malicious code designed to interfere with cryptocurrency transactions. Researchers found that the malware could modify wallet addresses during browser-based transactions by targeting functions such as fetch, XMLHttpRequest, and cryptocurrency wallet APIs.

Unlike some other supply chain attacks, the malware used in the debug and chalk incident did not rely on npm installation scripts to execute. Instead, it operated through browser-side interception techniques designed to manipulate transactions before users approved them.

Security researchers estimated that the attackers collected approximately $600 from the wallet-draining activity linked to the campaign.

Attribution Evidence Remains Under Review

While Amazon connected the incidents to a North Korean-linked group, researchers noted that the publicly available evidence supporting the attribution is limited.

Amazon cited overlapping techniques, malicious code similarities, and shared infrastructure indicators but did not publicly disclose detailed evidence connecting each individual compromise. The attribution of the debug, chalk, and typo-crypto incidents currently relies primarily on Amazon’s assessment.

Other security companies have separately linked the axios compromise to North Korean cyber activity. Google attributed the campaign to UNC1069, while Microsoft associated it with the group known as Sapphire Sleet, which overlaps with several other industry-tracked names.

Questions Raised Over typo-crypto Package Evidence

Amazon also identified a smaller npm package called typo-crypto as an earlier test campaign. The company said the package contained malicious code similar to techniques later used in attacks against more popular packages.

However, security analysts noted differences between the typo-crypto incident and the other compromises. Unlike a typical maintainer takeover followed by a malicious update, available registry information suggests typo-crypto may have been created as a malicious package from its initial publication.

Further analysis also raised questions about some technical indicators, including differences between reported malware hashes and files available from the npm registry.

npm Strengthens Security Measures After Supply Chain Attacks

The incidents highlight ongoing risks in open-source software ecosystems, where a single compromised package can affect millions of developers and applications.

The npm platform has introduced additional security measures, including changes to dependency lifecycle scripts and malware scanning for newly published packages. Experts warn, however, that these protections do not eliminate risks involving stolen maintainer accounts or social engineering attacks.

Security professionals continue to recommend that developers verify package updates carefully, use trusted authentication methods, and monitor dependencies for unexpected changes.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO