Back to advisories

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

North Korea's Sapphire Sleet compromised npm packages debug and chalk (2B+ weekly downloads) by phishing maintainers with lookalike domains and injecting wallet-draining malware. This is part of a 12-month campaign hitting at least four packages. Any developer or application using these packages is at risk of supply chain compromise and potential credential/wallet theft.

CRITICALAdvisoryJul 31, 2026
Action required
Immediately audit your npm dependencies for debug and chalk versions from September 2025 onward. Check application logs and process execution for suspicious wallet or crypto activity. If affected versions are in use, rotate credentials, revoke tokens, and upgrade to patched releases. Hunt for any other typo-squatted or unusual package installations in your build pipelines.
Affected products
debugchalk