Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Multifaceted Attribution Scandal: The Unsettling Case of Amazon npm Hijack


Amazon has assigned a medium confidence level to its attribution that North Korea's Sapphire Sleet group was responsible for the September 2025 npm package hijack of debug and chalk. However, concerns remain regarding the reliability of Amazon's evidence, including gaps in its analysis and questionable attribution assumptions.

  • The September 2025 npm package hijack was linked to North Korea's Sapphire Sleet group, according to Amazon Threat Intelligence.
  • A Trojanized file in the typo-crypto package in March 2025 led to the compromise of at least 18 packages with over 2 billion weekly downloads.
  • Amazon attributes the incident to North Korea based on shared tradecraft, trojanized packages, post-install hooks, code reuse, and overlapping command-and-control indicators.
  • The malicious activity appears to be financially motivated, with initial wallets netting around $600.
  • Some analysts have questioned the validity of Amazon's attribution due to inconsistencies in evidence, such as a registry listing still existing for the compromised package.


  • Amazon has recently revealed that the September 2025 npm package hijack, which saw the debug and chalk packages compromised, was linked to North Korea's Sapphire Sleet group. The incident, initially perceived as a crypto theft, took on new significance when Amazon Threat Intelligence conducted an in-depth analysis and assigned a medium confidence level to its findings.

    According to the report published by Amazon, the hijack of npm packages occurred after the Sapphire Sleet group, which was attributed to Microsoft earlier, had planted a Trojanized file in the typo-crypto package in March 2025. The incident unfolded when a maintainer was socially engineered, and an update was published, leading to the compromise of at least 18 packages with over 2 billion weekly downloads between them.

    Amazon's attribution is based on shared tradecraft across the campaigns, trojanized packages, post-install hooks, code reuse, and overlapping command-and-control indicators. The company describes the pattern as financially motivated, suggesting that the malicious activity was aimed at netting a substantial sum of money. According to Socket, the initial wallets had netted around $600.

    The analysis conducted by Amazon reveals that the malicious file posed as the legitimate core-js package inside the repository and triggered on a hash input beginning 0098273. It pulled an operating-system-specific second stage from a hardcoded C2, which was obfuscated with base64 over an XOR cipher keyed to 01042025. The network indicators associated with this incident include npmjs[.]store and 216[.]74[.]123[.]126.

    However, the extent of Amazon's evidence is not without controversy. While the company attributes the incident to North Korea, some analysts have questioned the validity of its attribution. For instance, a Hacker News article revealed that the registry listing for typo-crypto@4.3.0 still exists and remains installable, with no detectable malware or malicious activity. Moreover, the publishing account does not match the developer named in the package's author field.

    Furthermore, an earlier record published by Amazon Inspector has also raised questions about the accuracy of its attribution. The Hacker News checked this record on July 30, 2026, and found that typo-crypto@4.3.0 is still published and remains installable without any malicious activity. This raises concerns regarding the reliability of Amazon's evidence and whether it fully addresses the question at hand.

    Amazon's attribution has sparked debate among cybersecurity experts and researchers. On one hand, some agree with Amazon's assessment that North Korea's Sapphire Sleet group was responsible for the hijack. However, others have pointed out gaps in Amazon's evidence and called into question its claims of financial motivation behind the incident.

    While Amazon's analysis provides valuable insights into the motivations and methods employed by threat actors, further scrutiny is warranted to ensure a comprehensive understanding of this complex scenario. As the cybersecurity landscape continues to evolve, it is crucial for organizations to stay vigilant and maintain robust defenses against sophisticated threats like these.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Multifaceted-Attribution-Scandal-The-Unsettling-Case-of-Amazon-npm-Hijack-ehn.shtml

  • https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html


  • Published: Thu Jul 30 02:46:50 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us