hacker-news · Crawled Jul 30, 2026

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

4 IoCs 2 Actors
Read original article ↗

AI Summary

Amazon Threat Intelligence attributes the September 2025 compromise of the npm packages debug and chalk to the North Korean threat actor Sapphire Sleet, also linked to prior attacks on axios and typo-crypto. The attacks began with social engineering of maintainers, followed by malicious updates containing trojanized code. The debug and chalk incident involved a browser-side interceptor that hijacked cryptocurrency transactions by rewriting wallet addresses, while other campaigns used post-install hooks and command-and-control infrastructure. Amazon ties the campaigns together through shared tradecraft, code reuse, and overlapping C2 indicators, though some technical discrepancies exist in the evidence.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain npmjs[.]store Details →
IP 216[.]74[.]123[.]126 Details →
Filename core.js Details →
SHA-256 0098273 Details →

MITRE ATT&CK TTPs 10 techniques