Return to Threats

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

thehackernews.com 2026-07-30 AI supply chain Critical

What Happened

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the

Why It Matters

According to Amazon Threat Intelligence, the September 2025 compromise of the highly popular npm libraries debug and chalk—impacting at least 18 packages with roughly 2 billion weekly downloads—has now been attributed to a North Korea-linked threat actor known as Sapphire Sleet.[2][3][8][9] The attackers phished a maintainer via a lookalike npm domain and then pushed wallet-draining malware through trusted packages, turning the open-source ecosystem itself into a distribution channel for financially motivated attacks.[2][8][16] This is part of a broader, coordinated supply chain campaign by the same DPRK-linked group that later compromised axios and other packages, illustrating how a single maintainer account can become a systemic risk to downstream users and AI-powered systems that rely on JavaScript and npm tooling.[1][3][7][14] From a RealGround perspective, the incident underscores the need for rigorous AI supply chain governance: organizations should maintain SBOMs for AI-related services, enforce strict controls on developer credentials and publishing tokens, and continuously monitor and test build pipelines and agent frameworks for dependency hijacks and malicious pa

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html

Talk to AI CISO