ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Open Source

Amazon attributes debug and chalk npm hijack to North Korea’s Sapphire Sleet

Source headline: Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Threat level High
Signal strength 78/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Amazon says North Korea is behind a hijack of the npm packages debug and chalk. A maintainer was reportedly tricked via a lookalike npm domain. After initial access, a wallet-draining script was published into many packages. The malicious versions were available for months while attracting massive public download volumes. Developers using these packages should audit for tampered dependencies and consider lockfile and integrity checks.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#supply-chain #npm #north-korea #sapphire-sleet #wallet-drainer
Original reporting The Hacker News Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Open original source