[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzSExMaZ2kj-o0tQfAG5Nz9-n7RX1mc7Aei_Fl6qBnKM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"5d3a77c0-6cde-4506-b6f4-04e29ae3c82f","north-koreas-sapphire-sleet-hijacks-npm-packages-with-2b-weekly-downloads-via-maintainer-phishing","5ba0db94-b0b6-4eb7-ad88-8d82a4ba98b3","North Korea's Sapphire Sleet Hijacks npm Packages with 2B+ Weekly Downloads via Maintainer Phishing","The Sapphire Sleet threat group compromised the widely-used npm packages 'debug' and 'chalk' by phishing their maintainers through lookalike domains, then injecting wallet-draining scripts into packages downloaded billions of times weekly. This attack illustrates how open-source supply chain trust can be weaponized at massive scale — a single compromised maintainer account becomes a vector into millions of downstream applications and end-user systems. The discovery of a March 2025 'typo-crypto' test package suggests the campaign was deliberate and rehearsed, highlighting the sophistication of nation-state actors targeting developer ecosystems. The incident underscores that even foundational, ubiquitous packages are high-value targets precisely because their trustworthiness is rarely questioned.","**Immediate actions:**\n- Audit all project dependencies for the affected package versions (debug, chalk) and update to verified clean releases immediately.\n- Enable npm package integrity verification (e.g., lockfile enforcement and checksum validation) across all CI\u002FCD pipelines.\n- Monitor for unexpected outbound network connections or crypto-wallet API calls originating from build or runtime environments.\n\n**Long-term improvements:**\n- Implement a software composition analysis (SCA) tool to continuously monitor open-source dependencies for tampering, malicious code injection, and known-bad package versions.\n- Establish a vetted internal package mirror or registry proxy so all npm installs are reviewed before reaching developer machines.\n- Enforce multi-factor authentication (MFA) and phishing-resistant credentials (e.g., hardware security keys) for all maintainer accounts on public package registries.\n\n**Detection measures:**\n- Subscribe to threat intelligence feeds and npm security advisories to receive real-time alerts when popular packages are flagged as compromised.\n- Deploy runtime application self-protection (RASP) or eBPF-based monitoring to detect anomalous behavior — such as crypto wallet access — introduced through third-party libraries.\n- Conduct periodic reviews of transitive dependencies to identify high-risk packages maintained by single individuals vulnerable to social engineering.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Cybersecurity Supply Chain Risk Management","NIST SP 800-218: Secure Software Development Framework (SSDF) – PW.4 (Reuse Existing, Well-Secured Software)","NIST CSF 2.0: ID.SC-4 (Suppliers are assessed for risk)","SLSA Supply Chain Levels for Software Artifacts – Provenance Verification","CISA Secure by Design: Dependency Management Guidance","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-7: Software, Firmware, and Information Integrity","OpenSSF Scorecard: Dependency Pinning and Token Permissions","published","2026-07-30T08:21:37.803824+00:00","2026-07-30T08:21:37.52+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Famazon-links-debug-and-chalk-npm-hijack.html","amazon-links-debug-and-chalk-npm-hijack-to-north-korea-s-sapphire-sleet-c44618","Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]