Interestana
Home/News/Amazon Links npm Package Hijack to North Korea
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Amazon Links npm Package Hijack to North Korea

Amazon Links npm Package Hijack to North Korea

Amazon has attributed the September 2025 hijacking of the widely used npm packages debug and chalk to North Korea, identifying the threat actor as Sapphire Sleet. This incident, which initially appeared as a cryptocurrency theft, involved a maintainer being phished through a lookalike npm domain. A wallet-draining script was subsequently injected into at least 18 packages, collectively downloaded over 2 billion times weekly. The original analyses by Aikido and Wiz did not attribute the attack to a specific nation-state actor.

Sapphire Sleet, also known as Lazarus Group or APT38, is a state-sponsored hacking collective linked to the North Korean government. This group is notorious for its sophisticated cyber operations, often aimed at generating revenue for the regime through illicit cryptocurrency activities and cyber espionage. Their tactics frequently involve social engineering, supply chain attacks, and the exploitation of vulnerabilities in software development pipelines. The targeting of npm packages, which are fundamental components in many software development projects, represents a significant escalation in supply chain attack vectors, potentially impacting a vast number of downstream applications and services.

The hijack of debug and chalk, both critical libraries within the Node.js ecosystem, highlights the vulnerability of open-source software supply chains. The debug package is a widely adopted debugging utility, while chalk is a popular library for terminal string styling. The compromise of these packages could have allowed Sapphire Sleet to distribute malicious code to developers worldwide, potentially leading to further infections, data exfiltration, or the theft of sensitive information. The scale of downloads for these packages underscores the potential reach and impact of such a supply chain attack.

Amazon's attribution, detailed in a security bulletin released on March 19, 2024, provides a crucial link between the technical execution of the attack and a specific state-sponsored entity. This information is vital for cybersecurity professionals and organizations relying on these packages to implement appropriate defensive measures and threat intelligence. The ongoing efforts by Amazon and other security researchers to track and attribute such attacks are essential for understanding the evolving landscape of cyber threats and for developing more robust security protocols within the open-source community.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next