AUGUST 12, 2026
Subscribe
Global Press Media · World Report
Technology

State-Sponsored Cyberattack: Amazon Attributes 2025 npm Hijacks to North Korea

State-Sponsored Cyberattack: Amazon Attributes 2025 npm Hijacks to North Korea

New intelligence from Amazon has linked a significant supply chain compromise involving the popular npm packages 'debug' and 'chalk' in September 2025 directly to North Korea's state-sponsored cyber group, Sapphire Sleet. This attribution dramatically shifts the understanding of an incident that for ten months was publicly considered a relatively straightforward case of cryptocurrency theft.

The initial reports surrounding the September 2025 compromise indicated a sophisticated phishing operation. A maintainer responsible for the affected packages was reportedly targeted through a meticulously crafted lookalike npm domain, designed to steal credentials. Once access was gained, a malicious script was subsequently injected into at least 18 different npm packages, designed to drain cryptocurrency wallets.

Amazon's findings elevate the incident from common cybercrime to a matter of national security, suggesting a more strategic and hostile intent behind the attack. Sapphire Sleet, a group widely associated with the Democratic People's Republic of Korea, is known for its advanced persistent threat activities, often targeting critical infrastructure and financial institutions for espionage or illicit funding.

Source: feedburner
Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related