# Amazon Traces npm Package Hijacking to North Korean Group

*Published July 31, 2026*
*Source: [https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html](https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html)*

## Executive Summary

Amazon has linked the hijacking of npm packages debug and chalk to a North Korean group, revealing a pattern of phishing maintainers to inject malicious scripts. The attribution highlights ongoing threats in supply chain security and the need for enhanced protective measures.

## Article

Amazon has attributed the hijacking of npm packages debug and chalk in September 2025 to actors linked to North Korea. This incident, previously seen as a case of crypto theft, involved phishing a maintainer to inject a wallet-draining script into at least 18 packages, collectively seeing over 2 billion weekly downloads. Amazon's recent report connects this event to the same group responsible for the March 2026 axios compromise and a smaller package incident in March 2025. 

Amazon's investigation revealed a pattern of socially engineering a trusted maintainer and publishing malicious updates. While the initial reports from Aikido and Wiz did not link the incident to North Korea, Amazon's medium-confidence assessment now does, although the evidence provided is limited. The attackers used shared tradecraft, such as trojanized packages and overlapping command-and-control indicators, to execute their schemes. 

The compromised packages like typo-crypto served as potential test runs before targeting more popular ones. Despite the lack of new compromises, the evidence published by Amazon remains thin, particularly for the debug and chalk incidents. However, the malicious core.js file, which masqueraded as core-js, was confirmed to pull a second-stage payload from a hardcoded source. 

Other cybersecurity firms, such as Google and Microsoft, have linked the axios compromise to groups like UNC1069 and Sapphire Sleet, which aligns with Amazon's findings. Aikido has also supported the connection to North Korea, citing previous overlaps in command-and-control infrastructure. Meanwhile, npm has taken steps to mitigate such risks by implementing pre-install malware scans for new packages, although older packages remain unaffected by these measures.
