Skip to main content
CyberSingle-sourceMedium
5.5

Amazon attributes 2025 npm supply chain attack to North Korean threat actor Sapphire Sleet

Amazon security researchers have linked the 2025 hijacking of 'debug' and 'chalk' npm packages to the North Korean state-sponsored group Sapphire Sleet. The campaign compromised at least 18 packages with over 2 billion weekly downloads to facilitate cryptocurrency wallet theft. This attribution highlights the continued use of software supply chain poisoning by North Korean actors to generate illicit revenue.

The Hacker Newsabout 21 hours agoKP, USengCredibility 52%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.5

Intelligence Tags

Entities

countrycountrycountryconcept
Source

Related signals

8 found