CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3495

As cited

Copy frozen at (site build).

threat intel

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon attributed the September 2025 hijacking of the popular npm packages debug and chalk to North Korea's Sapphire Sleet threat group. The attack exploited a phished maintainer credential via a lookalike domain and injected wallet-draining code into at least 18 packages with combined weekly downloads exceeding 2 billion. The incident had been publicly documented as crypto theft for ten months before attribution.

Why it matters: Developers relying on debug and chalk or downstream packages need to assess their supply chain exposure to nation-state actors and verify current dependency versions for the injected malicious code.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary