Amazon ties debug and chalk npm hijacks to North Korean hackers

Amazon attributes the debug and chalk npm hijacks to the North Korean group behind the axios attack.

CSBadmin
2 Min Read

Amazon’s threat intelligence team has attributed the September 2025 hijack of the massively popular npm packages debug and chalk to North Korea, naming the same group it says orchestrated the March 2026 axios supply chain attack.

The episode was cataloged as crypto theft for ten months: a maintainer fell for a phish on a lookalike npm domain, and a wallet-draining script made its way into at least 18 packages that together draw more than 2 billion weekly downloads. Neither Aikido nor Wiz, which broke the story, tied it to a nation-state at the time.

Amazon’s July 29 research assesses with medium confidence that the axios group was behind the debug and chalk compromise, and further connects a trojanized package called typo-crypto, planted in March 2025, as a rehearsal a year ahead of the axios attack. The attribution spans four named packages across three campaigns in twelve months, each following the same blueprint: compromise a trusted maintainer, then ship a poisoned update.

No new compromise was reported. The response scope for debug and chalk, browser bundles and caches, remains unchanged; only the attribution is new. Amazon cites shared tradecraft, trojanized packages, post-install hooks, code reuse, and overlapping command-and-control indicators, though the evidence linking debug and chalk specifically is thinner than the headline.

Google independently assigned the axios attack to UNC1069, while Microsoft calls the actor Sapphire Sleet, which it says overlaps with UNC1069, BlueNoroff, and CryptoCore. Aikido pushed back on Amazon being the sole source, calling the connection “old news” and pointing to command-and-control overlap between the axios and Mastra incidents.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.