- Sources: BleepingComputer
- Summary: Amazon ties the typo-crypto trojan of March 2025, the September 2025 debug and chalk compromises, and the March 2026 axios compromise to the actor tracked as Sapphire Sleet, BlueNoroff, and Stardust Chollima. It reports the debug and chalk packages reached an estimated 10 percent of cloud environments within two hours, and axios at over 100 million weekly downloads. The attribution is stated at medium confidence and rests on shared tactics, command-and-control infrastructure, and operational similarities, so the linkage is the qualified part. Initial access in every case was social engineering of a maintainer rather than a registry flaw. The cited report enumerates no affected version numbers for debug, chalk, or axios, so no affected versions are asserted here and an operator cannot check a pinned dependency against this block alone. No Amazon first-party page for the report resolved in this run, so this block cites BleepingComputer alone.
- Why it matters: The named techniques are checkable by any team consuming npm: functionality split across several benign-looking packages, months of legitimate maintenance before the malicious commit, behaviour decoupled from package contents into external scripts and remotely fetched keys, payloads that delay execution until they detect a real developer or production environment, and registration of package names hallucinated by AI coding assistants so that a developer or an autonomous agent installs them.
- Follow-up: Track whether an Amazon first-party publication of this report becomes reachable, since the attribution and the confidence level currently rest on secondary coverage.
send feedback on this story