Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
AI Summary
Amazon has linked multiple npm supply-chain attacks to the North Korean threat actor Sapphire Sleet (also known as BlueNoroff and Stardust Chollima) with medium confidence. The attacks began in March 2025 with the compromise of the typo-crypto package, followed by the trojanization of widely used packages debug and chalk in September 2025, impacting an estimated 10% of cloud environments within two hours. In March 2026, the axios library—used by over 100 million developers weekly—was targeted, with malicious updates distributed after attackers socially engineered maintainers to gain access. The campaign used sophisticated tactics including delayed execution in real environments, multi-stage payloads, and 'slopsquatting' of AI-hallucinated package names to expand reach.
AI-extracted · verify before operational use