North Korea's npm hijack exposes a soft underbelly of open source
Amazon's threat team ties the 2025 'debug' and 'chalk' package takeovers to a Pyongyang-linked cluster, raising sharper questions about who polices the registries that ship the modern web.

At 06:10 UTC on 30 July 2026, Amazon's threat-intelligence unit published the clearest public account yet of how a North Korean cluster quietly walked away with credentials inside two of the most-downloaded JavaScript packages on the internet. The two operations, internalised by Amazon under the names "debug" and "chalk", reached at least 18 npm packages collectively responsible for more than two billion weekly downloads, according to a write-up carried by The Hacker News the same morning. Amazon's analysts attribute both intrusions to a group it tracks as Sapphire Sleet, and The Hacker News headline identifies Sapphire Sleet as a North Korean cluster.
The disclosure reframes an incident the security community first treated as opportunistic malware. It is now part of a sustained campaign. The Hacker News alert frames the two events as a connected sequence, and CyberScoop's own Telegram post at 02:10 UTC on 30 July frames an earlier, August 2025 package incident, in its own headline, as a "warm-up act" for the later axios hijack. The available items do not specify the technical details of either operation, and the editorial sequencing across both outlets is consistent only at the headline level.
What the thread items actually say
Most of the load-bearing details in this story come from three Telegram alerts and their linked web write-ups. The Hacker News alert at 06:10 UTC on 30 July names the two operations ("debug" and "chalk"), the cluster (Sapphire Sleet), the package count (at least 18), and the combined download footprint (more than two billion weekly downloads). CyberScoop's Telegram post at 02:10 UTC on 30 July frames the earlier intrusion as a warm-up for the axios hijack, and its linked web article carries the same framing. Crypto Briefing's post at 20:22 UTC on 30 July records that Amazon's shares jumped nearly 9% on earnings.
The thread items do not specify the download count of the malicious axios version, do not specify the exact August 2025 package that was compromised, do not name individual operators, and do not name the affected maintainers. The thread items also do not specify the criteria Amazon used to attribute both intrusions to Sapphire Sleet. The Hacker News headline identifies Sapphire Sleet as a North Korean-linked cluster. Readers should treat the chains of attribution as conveyed through the outlets' framing rather than as direct quotations from Amazon's bulletin.
A two-stage rehearsal, as far as the reporting goes
CyberScoop's reconstruction walks readers through the chronology that Amazon's investigators pieced together, per the outlet's own framing. In August 2025, the same cluster that would later hit axios compromised an npm package as a precursor operation. CyberScoop's headline calls the August intrusion a "warm-up act" for the later axios hijack. The available thread items do not specify the technical mechanism of the August compromise, the maintenance credentials involved, or the size and shape of the payload that was distributed. Monexus assessment: the editorial sequencing reported by both outlets points to a two-stage operation in which an earlier compromise served as preparation for a later, more consequential one, but the underlying mechanics are not laid out in the cited thread evidence.
When the same cluster returned to phish a maintainer of the axios library, the resulting malicious version was distributed widely before npm pulled it, per CyberScoop's framing. The exact download figure is not specified in the available thread items. The Hacker News alert reports that the wallet-draining payload reached at least 18 packages in total, with download counts that compound into the billions because of transitive dependencies. A developer who never types npm install debug still receives it, because some package they do install depends on it, which depends on something else, and so on. The attack surface, on this reading, is the registry itself.
Why a state actor would bother
Sapphire Sleet is, per The Hacker News and CyberScoop framing, a North Korean-linked cluster. The thread items do not specify which North Korean revenue unit it belongs to, whether it sits inside the larger Lazarus umbrella, or how its cryptocurrency theft proceeds are funnelled. Those are reasonable inferences from prior public reporting on Pyongyang-linked crypto theft, but they are not entailed by the three items in front of this article. The structural shift is the part that holds on the evidence: a single compromised maintainer account can reach the same downstream victims without the per-target friction of spear-phishing, and the registry itself becomes the distribution channel.
The maintainer economy is the part that does not require a cited source to be true on its face. Open-source maintainers are, in the great majority of cases, volunteers or under-resourced staff at small companies. They rotate credentials rarely, depend on email-based password resets, and publish under personal names rather than institutional ones. A state adversary willing to spend weeks inside a target's social graph can typically find the maintainer's second-factor reset flow faster than a benign user can. The thread items do not specify what GitHub or npm have rolled out by way of stronger defaults. Sapphire Sleet has already told the industry what it thinks of the answer.
What Amazon's account does not resolve
Amazon's write-up, as relayed by The Hacker News, is unusually detailed by industry standards and unusually restrained in its claims. It ties the two operations to Sapphire Sleet, per the outlet's characterisation. The thread evidence does not specify the criteria on which that attribution rests. It does not, in the cited excerpts, name individual operators, identify the specific maintainers whose accounts were compromised, or quantify the cryptocurrency actually stolen through the npm vector rather than through adjacent phishing.
The available reporting also does not specify whether any of the affected packages were used inside Amazon Web Services itself, or whether AWS customers were directly exposed. Amazon's security bulletin language, as carried by The Hacker News, treats the matter as a general supply-chain warning rather than as an admission of customer impact, and the cited items do not record a separate AWS disclosure. This publication treats that gap as a question still open, not as evidence of either safety or compromise.
A soft underbelly with a market cap
The npm incident lands in the same week Amazon reported quarterly results that sent its shares up nearly 9%, according to a brief carried by Crypto Briefing at 20:22 UTC on 30 July. The juxtaposition is uncomfortable but instructive. The same company whose cloud and advertising businesses beat consensus is also the company whose threat team has just sketched the most consequential open-source supply-chain compromise attributed to a nation state. The market reaction is the market's business; the policy question is everyone else's.
Open-source software is now load-bearing infrastructure for the global economy. A package downloaded two billion times a week is, in any meaningful sense, a public utility, yet it is governed by a maintainer in their spare time. The npm hijack does not change that fact; it makes the cost of leaving it unchanged legible. The choices ahead are not whether to regulate open source, but whether the registries themselves, the foundations that steward the most-used projects, and the corporate consumers who ship billions of dollars of products on top of them will move first, and at what speed. The next round of npm disclosures will tell.
Desk note: Monexus framed this as a structural supply-chain story rather than a cybercrime beat, on the grounds that the operative actor is a state-linked cluster rather than a financially motivated independent. Where the wire services led on technical mechanics, the piece foregrounds the maintainer-economics gap that makes the attack possible in the first place, and flags which claims are entailed by the cited thread items and which are not.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/thehackernews/9660
- https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
- https://t.me/CyberScoop/4465
- https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/
- https://cyberscoop.com/amazon-north-korea-open-source-software-at
- https://t.me/CryptoBriefing/18492
- https://t.me/thehackernews/9660
- https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
- https://t.me/CyberScoop/4465
- https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/
- https://cyberscoop.com/amazon-north-korea-open-source-software-at
- https://t.me/CryptoBriefing/18492