bleeping-computer · Crawled Jul 30, 2026

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

4 IoCs 2 Actors
Read original article ↗

AI Summary

Amazon has linked multiple npm supply-chain attacks to the North Korean threat actor Sapphire Sleet (also known as BlueNoroff and Stardust Chollima) with medium confidence. The attacks began in March 2025 with the compromise of the typo-crypto package, followed by the trojanization of widely used packages debug and chalk in September 2025, impacting an estimated 10% of cloud environments within two hours. In March 2026, the axios library—used by over 100 million developers weekly—was targeted, with malicious updates distributed after attackers socially engineered maintainers to gain access. The campaign used sophisticated tactics including delayed execution in real environments, multi-stage payloads, and 'slopsquatting' of AI-hallucinated package names to expand reach.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 4 extracted

Type Value Detail
Package typo-crypto Details →
Package debug Details →
Package chalk Details →
Package axios Details →

MITRE ATT&CK TTPs 15 techniques