North Korea behind the npm attacks on debug, chalk and axios: Amazon's attribution

Amazon attributes npm supply chain attacks on debug, chalk, and axios to North Korean group Sapphire Sleet, linking three campaigns over twelve months.

North Korea behind the npm attacks on debug, chalk and axios: Amazon's attribution
APT

Illustrative image generated with AI

Introduction

On July 29, 2026, Amazon Threat Intelligence attributed with medium confidence to the North Korean group Sapphire Sleet (also tracked as UNC1069 or BlueNoroff) the compromise of some of the most popular npm packages in the world. The investigation links for the first time under a single direction three campaigns that, over twelve months, hit debug and chalk in September 2025, axios in March 2026, and the malicious publication of the typo‑crypto package in March 2025.
Previous analyses by Aikido and Wiz had not identified a specific actor: now the picture is complete, outlining a persistent and financially motivated threat to the open-source software supply chain.

Technical Analysis

The three campaigns compared

The operations show different attack techniques, a sign of an adversary capable of adapting to security controls.

  • debug and chalk (September 2025): the attackers compromised the maintainers' accounts via social engineering and released infected updates. The injected malicious code – a browser-side script – did not exploit npm hooks like postinstall, but activated directly when web applications loaded the packages. Hooking into fetch, XMLHttpRequest, and cryptocurrency wallet APIs, the script silently modified transaction addresses (wallet drainer), without installing any persistence on the device.
  • typo‑crypto (March 31, 2025): a fake package imitating crypto‑js (typosquatting) published as an original package, not the result of a compromised maintainer. It contained an obfuscated trigger (XOR with key 01042025) that activated only under specific conditions, likely a testbed to refine techniques.
  • axios and Mastra (March 2026): access to the maintainers allowed insertion of lifecycle scripts (postinstall) that distributed a backdoor (WAVESHAPER.V2) for credential theft and lateral movement in development environments.

Evidence and discrepancies

The public evidence provided by Amazon – code reuse and shared C2 infrastructure (npmjs[.]store, IP 216.74.123.126) – does not detail, however, the exact glue between the campaigns. Some discrepancies emerge: the SHA256 hash indicated for core.js does not correspond to any file in the typo‑crypto archive and the package appears to be an original typosquatting operation, not a compromised maintainer.
Google and Microsoft had already attributed the attack on axios to the same actor, but no other vendor has publicly confirmed the connection also for debug, chalk and typo‑crypto. Aikido claims to have linked the incidents for some time thanks to overlaps in the C2s between axios and Mastra.

The platform response

npm v12 (released on July 8, 2026) disables by default dependency lifecycle scripts, removing the postinstall vector exploited by axios. However, it does not protect against attacks like the one on debug and chalk, where the malicious code was distributed directly in the package and executed by applications without the need for installation hooks.

Impact

The involved packages totaled over 2 billion weekly downloads. The documented immediate gain is only 600 USD (source Socket), but the systemic risk is enormous and still present.

  • End users: the script in debug/chalk intercepted crypto transactions in the browser, redirecting funds without leaving traces on the device.
  • Developers: the backdoor in axios allowed access to credentials and corporate environments, exposing internal networks and repositories.
  • Ecosystem: the compromise of trusted maintainers and the use of a fake package as a test demonstrate sophisticated planning and a concrete threat to the supply chain, exploiting the trust placed in open-source maintainers.

Mitigation

  • Update npm to the latest release (v12) to block lifecycle scripts; unfortunately, this is not enough for in-code attacks like those seen.
  • Protect maintainer accounts: enforcing two-factor authentication (2FA), monitoring anomalous accesses, and reviewing every suspicious update are essential countermeasures.
  • Detect compromise indicators: search your environments for the domain npmjs[.]store, the IP 216.74.123.126, and the file core.js. In web applications, check for any anomalous hooks on fetch, XMLHttpRequest, and wallet APIs.
  • Verify package integrity: compare hashes with those declared and be suspicious of packages where the author differs from the publishing account (case of typo‑crypto).
  • Remove unmaintained dependencies and consult advisories like OSV MAL‑2026‑3400 for typo‑[email protected].
  • Adopt analysis tools (e.g., Socket) to continuously monitor dependencies.

FAQ

1. Who is Sapphire Sleet and why does it target npm?

Sapphire Sleet (UNC1069, BlueNoroff, STARDUST CHOLLIMA) is a North Korean group specialized in financial attacks. It has targeted banks and cryptocurrency exchanges; today it has extended its operations to the software supply chain to distribute malicious code on a large scale, aiming at cryptocurrency theft or access to corporate networks. npm, with its millions of developers, is an ideal vector.

2. How can I check if I have been affected?

If your application used compromised versions of debug, chalk, or axios, inspect client-side bundles for scripts that intercept fetch or XMLHttpRequest. For axios, check network logs towards the C2 indicators (npmjs[.]store, 216.74.123.126) and verify the integrity of packages with hashes and audit tools. The presence of the file core.js is a red flag.

3. Why is npm v12 not sufficient to block these attacks?

npm v12 neutralizes lifecycle scripts (e.g., postinstall), the vector used by axios. However, the attacks on debug and chalk injected code directly into the JavaScript files of the package, executable without the need for installation hooks. Therefore, protection requires secure development practices, integrity checks, and continuous dependency monitoring, not only platform updates.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →