CyberSecurity News
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
AI summary
Amazon has attributed the hijacking of the npm packages debug and chalk to North Korea. The incident, which occurred in September 2025, involved a maintainer being phished through a lookalike npm domain, resulting in a wallet-draining script being pushed into at least 18 packages. These packages had a combined total of over 2 billion weekly downloads. The incident was initially reported as a crypto theft, but its attribution to North Korea has only now been made public by Amazon. The original reports from Aikido and Wiz did not include attribution for the incident. Amazon's findings provide new insight into the origins of the hijacking.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

