On point: The takeover of two widely distributed npm packages with over 2 billion weekly downloads combined is attributed to North Korean hackers.
Amazon has attributed the takeover of the npm packages Debug and Chalk in September 2025 to the North Korean hacker group Sapphire Sleet. For ten months, the incident was publicly treated as a cryptocurrency wallet theft resulting from a phishing attack on a package maintainer.
In September 2025, the npm package maintainer was lured into phishing via a fraudulent npm domain. Following successful compromise, wallet-draining scripts were injected into at least 18 packages that together recorded over 2 billion weekly downloads.
Initial analysis by Aikido and Wiz first documented the incident as a pure cryptocurrency wallet theft and made no attribution. Only Amazon’s retrospective investigation attributed the incident to the North Korean group Sapphire Sleet.
The ten-month delay in attribution reveals the typical pattern of supply chain attacks on the open-source ecosystem: due to the massive reach across millions of dependent projects, the true origin of the malicious code remains unclear initially. CISOs should re-examine package-lock files and provenance attestations for critical dependencies.
Source: thehackernews.com · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.