- Sources: primary
- Summary: Amazon Threat Intelligence attributes the axios, debug, chalk, and typo-crypto npm compromises to a single North Korea linked actor, tracked as SAPPHIRE SLEET and also reported as STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, at medium confidence. The shared entry path is social engineering of a trusted maintainer, and Amazon reports the typo-crypto malware to OSV as MAL-2026-3400. The post is dated 2026-07-29 and places the four compromises across a year: typo-crypto in March 2025, debug and chalk in September 2025, and axios in March 2026. Amazon publishes package hashes but no consolidated list of affected package versions, so there is no single place to check an installed version against. The axios package exceeds 100 million weekly downloads, and Amazon cites Wiz reporting that roughly 1 in 10 cloud environments were affected by the debug and chalk event within two hours.
- Why it matters: Four npm compromises previously treated as separate share one operator and one entry point, which makes maintainer account takeover the control point to harden rather than four package incidents to patch.
- Follow-up: Track whether further npm compromises are attributed to the same actor and whether the affected package versions are enumerated in one place.
send feedback on this story