← Back to Tech & Science

North Korean Group Linked to Major npm Package Hijacks for Crypto Theft

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SEOUL — Amazon Threat Intelligence has attributed a series of sophisticated cyberattacks targeting popular open-source software packages to North Korea's state-sponsored hacking unit, Sapphire Sleet. The group is responsible for hijacking the 'debug' and 'chalk' packages on the Node.js package manager (npm) in September 2025, as well as compromising the widely used 'axios' library earlier this year.

The attacks represent a coordinated campaign by UNC1069 to insert malicious code into trusted software dependencies. In March 2026, attackers infiltrated the axios repository, one of the most downloaded libraries in the JavaScript ecosystem. Amazon's analysis indicates that Sapphire Sleet utilized similar tactics during the September 2025 incidents involving debug and chalk, exploiting vulnerabilities in maintainer accounts to push compromised updates.

The primary objective of these intrusions is financial gain through cryptocurrency theft. The malicious scripts embedded within the packages are designed to drain digital wallets from infected systems and facilitate phishing operations against package maintainers. By compromising high-traffic libraries, the attackers ensure their payloads reach a vast number of downstream users across global networks.

Sapphire Sleet has long been identified as a financially motivated actor operating under North Korean direction. The group's recent activities mark an escalation in targeting software supply chains to bypass traditional network defenses. Instead of attacking individual endpoints directly, the unit compromises the foundational code that developers rely on, allowing malware to propagate automatically when users update their dependencies.

The September 2025 incidents involving debug and chalk occurred months before the axios compromise was publicly detailed, suggesting a sustained operational tempo rather than isolated events. Security researchers note that the technical signatures linking these three distinct attacks point to a single threat actor with advanced capabilities in social engineering and code injection.

As of July 30, 2026, no specific number of affected organizations or total financial losses have been disclosed by Amazon Threat Intelligence. The full scope of the wallet-draining scripts remains unclear as developers continue to audit their systems for signs of infection from the compromised libraries.

Questions remain regarding whether other popular npm packages are currently under active surveillance or preparation for similar attacks. While maintainers have since patched the affected repositories, the incident highlights the persistent vulnerability of open-source ecosystems to state-sponsored financial espionage. Industry experts warn that without enhanced authentication protocols and continuous monitoring of package integrity, supply chain attacks may become a more frequent vector for cryptocurrency theft.

Discussion

0 / 2000