[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:amazon-links-debug-and-chalk-npm-hijack-to-north-korea-s-sapphire-sleet-ms8pwqqz":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":15,"article_ids":16,"ioc_summary":18,"source_urls":19,"status":21,"expires_at":22,"created_at":23,"updated_at":24,"articles":25},"4a28777a-6769-4d22-9b03-7aaa2147362e","Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet","amazon-links-debug-and-chalk-npm-hijack-to-north-korea-s-sapphire-sleet-ms8pwqqz","North Korea's Sapphire Sleet compromised npm packages debug and chalk (2B+ weekly downloads) by phishing maintainers with lookalike domains and injecting wallet-draining malware. This is part of a 12-month campaign hitting at least four packages. Any developer or application using these packages is at risk of supply chain compromise and potential credential\u002Fwallet theft.","critical","advisory",[],[13,14],"debug","chalk","Immediately audit your npm dependencies for debug and chalk versions from September 2025 onward. Check application logs and process execution for suspicious wallet or crypto activity. If affected versions are in use, rotate credentials, revoke tokens, and upgrade to patched releases. Hunt for any other typo-squatted or unusual package installations in your build pipelines.",[17],"5ba0db94-b0b6-4eb7-ad88-8d82a4ba98b3",null,[20],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Famazon-links-debug-and-chalk-npm-hijack.html","active","2026-08-02T09:05:59.277+00:00","2026-07-31T09:06:03.084272+00:00","2026-07-31T09:10:08.180389+00:00",[26],{"id":17,"title":6,"url":20}]