Threat reportSupply ChainTL-2026-1760

Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign

criticalACTIVE

Amazon: North Korea's Sapphire Sleet (Stardust (TL-2026-1760) is a critical-severity supply-chain compromise, first published 2026-07-29 and last reviewed 2026-07-31. It is attributed to APT38 (North Korea) with medium confidence, affects npm / open-source JavaScript ecosystem axios, maps to 33 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 58 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
33MITRE ATT&CK
Actors
1APT38
Detection rules
9SPL · KQL · Sigma
IOCs
58Indicators of compromise

Key facts for TL-2026-1760

Threat ID
TL-2026-1760
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
APT38
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, financial-services, venture-capital, blockchain, cloud-computing
Target regions
Global
Detection rules
9
Indicators of compromise
58
Updates
2026-07-31 · revalidated 1× · latest source

Malware and tooling in Amazon: North Korea's Sapphire Sleet (Stardust

Malware and tooling: SILKBELL, WAVESHAPER

How Amazon: North Korea's Sapphire Sleet (Stardust works

Amazon attributes, with medium confidence, a string of npm supply-chain compromises spanning March 2025-2026 to the North Korean state-linked cluster tracked as Sapphire Sleet, Stardust Chollima, and UNC1069. The actor cultivated trust with package maintainers to obtain publishing access, then shipped obfuscated multi-stage postinstall droppers that deployed the cross-platform WAVESHAPER.V2 RAT across affected packages including axios (100M+ weekly downloads), debug, chalk, and typo-crypto.

Amazon's threat-intelligence team (CISO CJ Moses, AWS Senior Engineering Manager Rick Anthony) links four npm supply-chain incidents into a single North Korean campaign: the March 2025 compromise of typo-crypto (described internally as a low-stakes 'rehearsal'), the September 2025 mass compromise of debug, chalk, and 17 dependency-chain packages (ansi-styles, color-convert, strip-ansi, wrap-ansi, and others), and the March 2026 compromise of axios, one of the most-downloaded JavaScript HTTP client libraries. Across all four, the actor did not exploit a technical vulnerability — it built social rapport with maintainers holding legitimate publish rights (via phishing emails impersonating npm support, and in parallel efforts, fabricated video personas and cloned Slack/LinkedIn identities), then abused that trust to push malicious releases.

The September 2025 wave began when maintainer 'Qix' was phished via the domain npmjs.help (registered just three days prior) and lost control of the npm account behind debug, chalk, and 17 other high-download packages. The malicious code was a browser-side interceptor that wrapped fetch/XMLHttpRequest and wallet-signing interfaces (window.ethereum.request, Solana signing) to silently rewrite transaction recipients, spender addresses, and ERC-20 allowances before user signature — a crypto-clipper targeting ETH, BTC, SOL, TRON, LTC, and BCH. Wiz found the malicious code reached roughly 10% of scanned cloud environments within a two-hour exposure window, out of ~99% of environments that carried the targeted packages at all.

The March 2026 axios compromise used a different payload architecture: the hijacked maintainer account ('jasonsaayman') published axios@1.14.1 and axios@0.30.4, each carrying a new transitive dependency, plain-crypto-js@4.2.1, that was not a real axios dependency. Its postinstall hook ran a two-layer-obfuscated (reversed-Base64 plus XOR, key OrDeR_7077) JavaScript dropper (tracked by Google/Mandiant as SILKBELL) that fingerprinted the OS and pulled a platform-specific second-stage payload from sfrclak.com:8000/6202033 — a PowerShell implant on Windows, a C++ Mach-O binary on macOS, and a Python backdoor on Linux — all instances of the WAVESHAPER.V2 remote-access trojan. WAVESHAPER.V2 beacons every 60 seconds over HTTP POST with Base64-encoded JSON, spoofing an Internet Explorer 8 User-Agent and a fake packages.npm.org domain string in its body to blend in with registry traffic; it supports kill, rundir (filesystem enumeration), runscript (PowerShell/AppleScript/Shell execution), and peinject (reflective binary injection) commands. The dropper is self-erasing: it deletes setup.js and swaps the poisoned package.json for a clean package.md, removing the postinstall-trigger evidence from node_modules. A mirror package, @depup/axios, republished the payload within 17 minutes of the original malicious release, and forensic build-path strings inside the macOS binary ('Jain_DEV/client_mac/macWebT/macWebT') tie the implant to BlueNoroff's prior 'webT' module used in the RustBucket and Hidden Risk campaigns (2023-2024).

Google/Mandiant formally attributed the axios compromise to UNC1069 (aliased Sapphire Sleet, Stardust Chollima, BlueNoroff, CryptoCore, CageyChameleon, APT38, TA444), an actor active since at least 2018/2020 whose primary historical targeting is the cryptocurrency, venture-capital, and blockchain sectors. Amazon assesses with medium confidence that the same actor sits behind all four incidents (typo-crypto, debug, chalk, axios), and separately reports the same cluster has seeded an estimated 1,700 malicious packages across npm, PyPI, Go, and Rust since January 2025 — a related June 2026 Microsoft report documents a further Sapphire Sleet postinstall-payload compromise of the Mastra AI npm ecosystem, indicating the campaign is ongoing.

MITRE ATT&CK techniques used in TL-2026-1760

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1568 Dynamic Resolution

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Impact

T1565 Data Manipulation; T1657 Financial Theft

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Amazon: North Korea's Sapphire Sleet (Stardust

  • npm / open-source JavaScript ecosystem — axios
    Vulnerable versions: 1.14.1; 0.30.4
    Fixed in: Maintainer-published clean releases after removing the plain-crypto-js dependency; exact version numbers not confirmed in sourced reporting
  • npm / open-source JavaScript ecosystem — debug
    Vulnerable versions: 4.4.2
    Fixed in: Reverted/deprecated by npm within hours of detection
  • npm / open-source JavaScript ecosystem — chalk
    Vulnerable versions: 5.6.1
    Fixed in: Reverted/deprecated by npm within hours of detection
  • npm / open-source JavaScript ecosystem — typo-crypto
    Vulnerable versions: March 2025 release
    Fixed in: Removed from registry
  • npm / open-source JavaScript ecosystem — plain-crypto-js
    Vulnerable versions: 4.2.1
    Fixed in: Package removed/deprecated
  • npm / open-source JavaScript ecosystem — ansi-styles, color-convert, strip-ansi, wrap-ansi, ansi-regex, slice-ansi, is-arrayish, color-name, error-ex, color-string, simple-swizzle, has-ansi, supports-hyperlinks, chalk-template, backslash, supports-color, proto-tinker-wc
    Vulnerable versions: Versions published 2025-09-08 per Aikido/Wiz/Semgrep advisories
    Fixed in: Deprecated/reverted by npm and maintainers within hours

Remediation for Amazon: North Korea's Sapphire Sleet (Stardust

Patches

  • Upgrade to maintainer-confirmed clean releases of axios, debug, chalk, and every affected ansi/color-chain dependency once the compromised versions are deprecated on the registry.

Immediate actions

  • Rotate all secrets, API keys, tokens, and credentials on any system that installed axios 1.14.1/0.30.4, debug 4.4.2, chalk 5.6.1, any of the 17 co-compromised September 2025 ansi/color dependency-chain packages, or typo-crypto — treat the host as fully compromised and rotate from a clean device.
  • Block network egress to sfrclak.com and 142.11.206.73:8000 at the perimeter, proxy, and EDR layer.
  • Hunt for on-disk artifacts: %PROGRAMDATA%\wt.exe, %TEMP%\6202033.ps1, %TEMP%\6202033.vbs (Windows); /Library/Caches/com.apple.act.mond (macOS); /tmp/ld.py (Linux).
  • Audit lockfiles across all repos for plain-crypto-js, proto-tinker-wc@0.1.87, and @depup/axios; purge and reinstall dependencies from a verified-clean registry snapshot.

Workarounds

  • Pin dependency versions via lockfile with integrity hashes and disable automatic postinstall script execution until packages are verified against GHSA-3hfp-gqgh-xc5g, GHSA-fw8c-xr5c-95f9, and GHSA-2x9r-6wxq-hrr7.

Longer-term hardening

  • Set npm config ignore-scripts=true in CI/build pipelines by default and explicitly allowlist packages that require postinstall execution.
  • Require hardware-key (FIDO2/WebAuthn) 2FA for all package-maintainer and npm-publish-capable accounts; disable SMS/email-based 2FA fallback.
  • Adopt continuous software-composition-analysis scanning (e.g., Socket, Aikido, Wiz) that flags new dependency versions before they reach build pipelines.
  • Establish out-of-band, multi-channel verification for any maintainer trust-transfer event (co-maintainer additions, publish-access grants, 2FA resets), given this actor's documented use of fabricated video personas and cloned Slack/LinkedIn identities to build rapport before striking.

Weaknesses (CWE) in Amazon: North Korea's Sapphire Sleet (Stardust

CWE-506, CWE-829, CWE-494

Timeline of Amazon: North Korea's Sapphire Sleet (Stardust

Showing the 20 most recent tracked events.

  • UNC1069/Sapphire Sleet begins seeding an estimated 1,700 malicious packages across npm, PyPI, Go, and Rust as part of a broad open-source supply-chain campaign (Amazon and Google/Mandiant reporting places the start 'since January 2025').
  • typo-crypto npm package compromised — later described by Amazon CISO CJ Moses as a low-profile 'rehearsal' for the subsequent axios/debug/chalk operations.
  • Phishing domain npmjs.help registered, three days ahead of the debug/chalk attack, to impersonate npm support.
  • Maintainer acknowledged the debug/chalk compromise and began removing malicious versions roughly two hours after initial publication; ~2.6M downloads occurred during the exposure window and the payload reached an estimated 1 in 10 cloud environments.
  • A second package, proto-tinker-wc@0.1.87, is detected compromised via the same phished account at 16:58 UTC.
  • Aikido's threat-intel feed flags the compromised debug/chalk packages at 13:16 UTC, within roughly six minutes of the malicious publish.
  • npm maintainer 'Qix' (debug, chalk, and 17 other packages) is phished via npmjs.help and loses control of the account; malicious versions of debug@4.4.2, chalk@5.6.1, and 17 dependency-chain packages are published, embedding a browser-side crypto-transaction hijacker targeting window.ethereum and Solana signing.
  • Decoy package plain-crypto-js@4.2.0 is published, followed within hours by the malicious plain-crypto-js@4.2.1 dependency later used in the axios attack.
  • npm removes the compromised axios and plain-crypto-js packages, closing a roughly three-hour exposure window (00:21-03:29 UTC).
  • Elastic Security Labs files a GitHub Security Advisory for the compromised axios releases at approximately 01:50 UTC.
  • axios@1.14.1 and axios@0.30.4 are published from the hijacked maintainer account 'jasonsaayman', each pulling in plain-crypto-js@4.2.1 to drop the WAVESHAPER.V2 cross-platform RAT via a SILKBELL postinstall dropper; a mirror package, @depup/axios, republishes the payload within 17 minutes.
  • Microsoft publishes mitigation guidance for the axios npm supply-chain compromise and attributes the intrusion set to Sapphire Sleet.
  • Google/Mandiant formally attributes the axios compromise to UNC1069; the Cloud Security Alliance publishes a research note on the AI-vendor npm code-signing risk exposed by the incident.
  • CISA published an advisory on the axios npm supply-chain compromise.
  • Additional detail on the Mastra scope compromise: a dormant maintainer account was used to inject typosquatted dependency easy-day-js@1.11.22 (impersonating dayjs) across 140+ packages via caret-range resolution during a 01:12-02:36 UTC window; the dropper disabled TLS validation, harvested credentials from 166 browser extensions (11 password managers, a Deloitte enterprise credential wallet, and Zapier), and Aikido linked it to the axios campaign via shared Hostwinds infrastructure and matching dropper tradecraft.
  • Microsoft documents a related Sapphire Sleet postinstall-payload compromise of the Mastra AI npm package ecosystem, confirming continued campaign activity.
  • npm v12 released, disabling dependency lifecycle (post-install) scripts by default — closing the axios/Mastra postinstall vector but not the underlying maintainer-credential-compromise entry point.
  • npm began scanning newly published packages for malware; the scanning does not retroactively cover already-published packages such as typo-crypto@4.3.0, which remained installable.
  • Amazon publicly links Sapphire Sleet/Stardust Chollima/UNC1069 to the typo-crypto, debug, chalk, and axios compromises as a single maintainer-trust-abuse campaign (CyberScoop reporting).
  • The Hacker News and The Register published coverage of Amazon's attribution, noting the roughly 10-16 month gap between the original incidents and public actor attribution, and that Amazon's evidence chain does not explicitly map which indicator ties to which incident.

Update history for TL-2026-1760

Sources cited for Amazon: North Korea's Sapphire Sleet (Stardust

Detection coverage for TL-2026-1760

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1760 across Splunk SPL, Microsoft KQL and Sigma, covering 58 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
58 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1760

5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats