Back to all lessons
Awareness Lessons
2 months ago

North Korea's Sapphire Sleet Hijacks npm Packages with 2B+ Weekly Downloads via Maintainer Phishing

The Sapphire Sleet threat group compromised the widely-used npm packages 'debug' and 'chalk' by phishing their maintainers through lookalike domains, then injecting wallet-draining scripts into packages downloaded billions of times weekly. This attack illustrates how open-source supply chain trust can be weaponized at massive scale — a single compromised maintainer account becomes a vector into millions of downstream applications and end-user systems. The discovery of a March 2025 'typo-crypto' test package suggests the campaign was deliberate and rehearsed, highlighting the sophistication of nation-state actors targeting developer ecosystems. The incident underscores that even foundational, ubiquitous packages are high-value targets precisely because their trustworthiness is rarely questioned.

Tactical Insight

Immediate actions

  • Audit all project dependencies for the affected package versions (debug, chalk) and update to verified clean releases immediately.
  • Enable npm package integrity verification (e.g., lockfile enforcement and checksum validation) across all CI/CD pipelines.
  • Monitor for unexpected outbound network connections or crypto-wallet API calls originating from build or runtime environments.

Long-term improvements

  • Implement a software composition analysis (SCA) tool to continuously monitor open-source dependencies for tampering, malicious code injection, and known-bad package versions.
  • Establish a vetted internal package mirror or registry proxy so all npm installs are reviewed before reaching developer machines.
  • Enforce multi-factor authentication (MFA) and phishing-resistant credentials (e.g., hardware security keys) for all maintainer accounts on public package registries.

Detection measures

  • Subscribe to threat intelligence feeds and npm security advisories to receive real-time alerts when popular packages are flagged as compromised.
  • Deploy runtime application self-protection (RASP) or eBPF-based monitoring to detect anomalous behavior — such as crypto wallet access — introduced through third-party libraries.
  • Conduct periodic reviews of transitive dependencies to identify high-risk packages maintained by single individuals vulnerable to social engineering.