Amazon Ties North Korean Hacker Group to 18 npm Packages With 2 Billion Weekly Downloads
Amazon researchers linked the hijacking of 18 npm software packages to a hacking group tied to North Korea, identifying the campaign as Sapphire Sleet. The attack compromised programming libraries including debug and chalk, drawing at least 2 billion weekly downloads from developers worldwide.
The group planted malicious code in the target packages to steal cryptocurrency wallets. Researchers announced the findings during a media roundtable, noting the North Korean operation began more than a year prior to the main breach.
From the sources (4 posts)
@tweetthreatnewsAmazon researchers say a North Korea-linked group used tiny typo-crypto as a rehearsal before compromising axios and other open-source packages, using trusted maintainer access and hidden code. #NorthKorea #axios #typo-crypto
@cyberscoopnewsAmazon’s security researchers say a hacking group tied to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet’s most widely used programming tools. The company’s threat intelli
@ddimolfettaNorth Korea-linked hackers has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the known scope of DPRK’s efforts to access trusted code environments h
@thehackersnews🚨 Amazon links the 2025 'debug' and 'chalk' npm hijack to North Korea’s Sapphire Sleet. The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads. Read the full report: