SendTech Times
News
MARKET SIGNAL:

Amazon Attribution Moves npm Hijack Risk Back To Maintainer Accounts

Newsroom brief

Amazon Threat Intelligence linked the debug and chalk npm hijack to North Korea’s Sapphire Sleet, extending the supply-chain timeline while leaving public evidence gaps around older package records.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: The Hacker News
Amazon Attribution Moves npm Hijack Risk Back To Maintainer Accounts
Image source: The Hacker News

A North Korea attribution for the debug and chalk npm hijack changes the incident from a one-off wallet theft into part of a longer maintainer-account risk pattern.

The Hacker News reported that Amazon Threat Intelligence now connects the September 2025 compromise to Sapphire Sleet, while the public evidence still leaves some package-level links unresolved.

Amazon Threat Intelligence said in its July 29 research that the same group behind the March 2026 axios compromise was responsible.

Reports from Aikido and Wiz put the earlier debug and chalk incident across at least 18 packages with more than 2 billion weekly downloads, after a phishing-led npm compromise placed wallet-draining code in the package chain.

Attribution Extends The npm Supply-Chain Timeline

The new assessment reaches beyond the axios case that Google tied to UNC1069 and Microsoft tied to Sapphire Sleet.

Amazon also connects a smaller March 2025 package, typo-crypto, to the same activity cluster, placing a low-download test package before the larger axios incident.

The campaigns share a dependency on trusted developer paths rather than a single software flaw.

Maintainer phishing, malicious package updates and registry trust all sit inside the attack chain, so rotating credentials after an account compromise may not remove already-published malicious code from build systems, browser bundles or local caches.

Package Records Leave Some Links Unproven

The evidence is uneven across the packages.

The axios attribution has support from Google and Microsoft, while the debug and chalk link depends on Amazon's tradecraft comparison and command-and-control indicators.

No other public vendor report in the record named an actor for debug, chalk or typo-crypto.

The package record for typo-crypto also complicates the update narrative.

The registry entry checked on July 30, 2026, showed version 4.3.0 as still published and installable.

Its only listed release landed on March 31, 2025, and the creation and publication timestamps were separated by 204 milliseconds.

Amazon listed the registry timestamps as a first-publish sequence, and the available public package record does not list an earlier clean version.

Amazon's indicator list has another limitation.

The public indicators contain a mismatch between the SHA256 value Amazon labels as the package hash and the files served in the tarball, while core.js still contains the trigger value and XOR key named in the research.

The package-level evidence chain remains unreconciled for every compromise in the public record.

Registry Changes Narrow One Delivery Path

The npm ecosystem has already changed some defaults. npm v12, shipped on July 8, disables dependency lifecycle scripts by default, reducing the post-install route used in the axios compromise.

The report said that the registry also began scanning newly published packages for malware on July 28 before they become installable.

The new defaults narrow one execution route, but account takeover remains a separate supply-chain problem for debug, chalk and axios.

Aikido's comments to The Hacker News separated the debug and chalk method from lifecycle or install scripts, while axios and Mastra used that route.

Socket's comment to the outlet put the remaining entry point at the trusted maintainer account after social engineering.

For security teams, the operating record points to account protection, package provenance and cache review as one response problem.

Amazon's public post does not specify which evidence ties each older npm compromise to Sapphire Sleet.

Share this article
inXf

Related articles

More
CrowdStrike Sees AI Attacks Converging With SaaS And Cloud Identity Risk
Cybersecurity

CrowdStrike Sees AI Attacks Converging With SaaS And Cloud Identity Risk

Back End News framed CrowdStrike’s 2026 threat outlook around AI-enabled attacks, resilient ransomware and cloud identity exposure as enterprises expand AI and SaaS use.

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk
Cybersecurity

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk

Ars Technica reported that ESET found 11 old UEFI shim images that Microsoft still trusted even after known defects. Microsoft revoked the shims in its June patch release, while the reason the lapse lasted for years remains outside the public account.

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk
Cybersecurity

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk

Socket, Ox Security and StepSecurity said they detected wallet-stealing code in @injectivelabs/sdk-ts npm package version 1.20.21 after an Injective Labs contributor account was compromised. Socket said the malicious release was downloaded 310 times before deprecation, while Ox Security counted 87 direct dependencies and described a six-figure cumulative download count across dependent packages.

Target-Locked Malware Narrows Central Asia Cyber Espionage Risk
Cybersecurity

Target-Locked Malware Narrows Central Asia Cyber Espionage Risk

Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia and Syria.

Selfie Video Recovery Gives Google Accounts A New Login Path
Cybersecurity

Selfie Video Recovery Gives Google Accounts A New Login Path

Google is adding opt-in selfie video account recovery while keeping Workspace, child and Advanced Protection accounts outside the feature, giving consumer users another login path tied to facial verification controls.

AI Reprices Cybercrime Risk Around Phishing And Deepfakes
Cybersecurity

AI Reprices Cybercrime Risk Around Phishing And Deepfakes

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says generative AI is reducing the cost and skill needed for phishing and social-engineering attacks. The piece frames AI cyber risk as an operating-control problem for payment approvals, access requests, employee training, simulations, defensive tools and board-level governance.

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda
Cybersecurity

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda

CISA added exploited Android and Linux vulnerabilities to its Known Exploited Vulnerabilities catalog. The Android flaw affects Android 14 through 16, while the Linux issue centers on older kernel branches and cgroups v1 container environments. The immediate test is whether agencies and infrastructure operators apply vendor updates or mitigations by CISA's June 5 deadline.

Australia Orders Legacy System Stocktake After AI Portal Exposure
Cybersecurity

Australia Orders Legacy System Stocktake After AI Portal Exposure

Australia’s Home Affairs department ordered Commonwealth entities to inventory legacy technology and produce risk plans by March 2027 after an AI-agent incident exposed non-public data from an older Medicare statistics portal.

Keep Reading

More Stories

Latest
Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.