Threat reportSupply ChainTL-2026-1760
Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign
Amazon: North Korea's Sapphire Sleet (Stardust (TL-2026-1760) is a critical-severity supply-chain compromise, first published 2026-07-29 and last reviewed 2026-07-31. It is attributed to APT38 (North Korea) with medium confidence, affects npm / open-source JavaScript ecosystem axios, maps to 33 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 58 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 33MITRE ATT&CK
- Actors
- 1APT38
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 58Indicators of compromise
Key facts for TL-2026-1760
- Threat ID
- TL-2026-1760
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- APT38
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cryptocurrency, financial-services, venture-capital, blockchain, cloud-computing
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 58
- Updates
- 2026-07-31 · revalidated 1× · latest source
Malware and tooling in Amazon: North Korea's Sapphire Sleet (Stardust
Malware and tooling: SILKBELL, WAVESHAPER
How Amazon: North Korea's Sapphire Sleet (Stardust works
Amazon attributes, with medium confidence, a string of npm supply-chain compromises spanning March 2025-2026 to the North Korean state-linked cluster tracked as Sapphire Sleet, Stardust Chollima, and UNC1069. The actor cultivated trust with package maintainers to obtain publishing access, then shipped obfuscated multi-stage postinstall droppers that deployed the cross-platform WAVESHAPER.V2 RAT across affected packages including axios (100M+ weekly downloads), debug, chalk, and typo-crypto.
Amazon's threat-intelligence team (CISO CJ Moses, AWS Senior Engineering Manager Rick Anthony) links four npm supply-chain incidents into a single North Korean campaign: the March 2025 compromise of typo-crypto (described internally as a low-stakes 'rehearsal'), the September 2025 mass compromise of debug, chalk, and 17 dependency-chain packages (ansi-styles, color-convert, strip-ansi, wrap-ansi, and others), and the March 2026 compromise of axios, one of the most-downloaded JavaScript HTTP client libraries. Across all four, the actor did not exploit a technical vulnerability — it built social rapport with maintainers holding legitimate publish rights (via phishing emails impersonating npm support, and in parallel efforts, fabricated video personas and cloned Slack/LinkedIn identities), then abused that trust to push malicious releases.
The September 2025 wave began when maintainer 'Qix' was phished via the domain npmjs.help (registered just three days prior) and lost control of the npm account behind debug, chalk, and 17 other high-download packages. The malicious code was a browser-side interceptor that wrapped fetch/XMLHttpRequest and wallet-signing interfaces (window.ethereum.request, Solana signing) to silently rewrite transaction recipients, spender addresses, and ERC-20 allowances before user signature — a crypto-clipper targeting ETH, BTC, SOL, TRON, LTC, and BCH. Wiz found the malicious code reached roughly 10% of scanned cloud environments within a two-hour exposure window, out of ~99% of environments that carried the targeted packages at all.
The March 2026 axios compromise used a different payload architecture: the hijacked maintainer account ('jasonsaayman') published axios@1.14.1 and axios@0.30.4, each carrying a new transitive dependency, plain-crypto-js@4.2.1, that was not a real axios dependency. Its postinstall hook ran a two-layer-obfuscated (reversed-Base64 plus XOR, key OrDeR_7077) JavaScript dropper (tracked by Google/Mandiant as SILKBELL) that fingerprinted the OS and pulled a platform-specific second-stage payload from sfrclak.com:8000/6202033 — a PowerShell implant on Windows, a C++ Mach-O binary on macOS, and a Python backdoor on Linux — all instances of the WAVESHAPER.V2 remote-access trojan. WAVESHAPER.V2 beacons every 60 seconds over HTTP POST with Base64-encoded JSON, spoofing an Internet Explorer 8 User-Agent and a fake packages.npm.org domain string in its body to blend in with registry traffic; it supports kill, rundir (filesystem enumeration), runscript (PowerShell/AppleScript/Shell execution), and peinject (reflective binary injection) commands. The dropper is self-erasing: it deletes setup.js and swaps the poisoned package.json for a clean package.md, removing the postinstall-trigger evidence from node_modules. A mirror package, @depup/axios, republished the payload within 17 minutes of the original malicious release, and forensic build-path strings inside the macOS binary ('Jain_DEV/client_mac/macWebT/macWebT') tie the implant to BlueNoroff's prior 'webT' module used in the RustBucket and Hidden Risk campaigns (2023-2024).
Google/Mandiant formally attributed the axios compromise to UNC1069 (aliased Sapphire Sleet, Stardust Chollima, BlueNoroff, CryptoCore, CageyChameleon, APT38, TA444), an actor active since at least 2018/2020 whose primary historical targeting is the cryptocurrency, venture-capital, and blockchain sectors. Amazon assesses with medium confidence that the same actor sits behind all four incidents (typo-crypto, debug, chalk, axios), and separately reports the same cluster has seeded an estimated 1,700 malicious packages across npm, PyPI, Go, and Rust since January 2025 — a related June 2026 Microsoft report documents a further Sapphire Sleet postinstall-payload compromise of the Mastra AI npm ecosystem, indicating the campaign is ongoing.
MITRE ATT&CK techniques used in TL-2026-1760
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1568 Dynamic Resolution
Initial Access
T1195 Supply Chain Compromise; T1566 Phishing
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Impact
T1565 Data Manipulation; T1657 Financial Theft
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information
defense-impairment
Affected products and versions in Amazon: North Korea's Sapphire Sleet (Stardust
- npm / open-source JavaScript ecosystem — axios
Vulnerable versions: 1.14.1; 0.30.4
Fixed in: Maintainer-published clean releases after removing the plain-crypto-js dependency; exact version numbers not confirmed in sourced reporting - npm / open-source JavaScript ecosystem — debug
Vulnerable versions: 4.4.2
Fixed in: Reverted/deprecated by npm within hours of detection - npm / open-source JavaScript ecosystem — chalk
Vulnerable versions: 5.6.1
Fixed in: Reverted/deprecated by npm within hours of detection - npm / open-source JavaScript ecosystem — typo-crypto
Vulnerable versions: March 2025 release
Fixed in: Removed from registry - npm / open-source JavaScript ecosystem — plain-crypto-js
Vulnerable versions: 4.2.1
Fixed in: Package removed/deprecated - npm / open-source JavaScript ecosystem — ansi-styles, color-convert, strip-ansi, wrap-ansi, ansi-regex, slice-ansi, is-arrayish, color-name, error-ex, color-string, simple-swizzle, has-ansi, supports-hyperlinks, chalk-template, backslash, supports-color, proto-tinker-wc
Vulnerable versions: Versions published 2025-09-08 per Aikido/Wiz/Semgrep advisories
Fixed in: Deprecated/reverted by npm and maintainers within hours
Remediation for Amazon: North Korea's Sapphire Sleet (Stardust
Patches
- Upgrade to maintainer-confirmed clean releases of axios, debug, chalk, and every affected ansi/color-chain dependency once the compromised versions are deprecated on the registry.
Immediate actions
- Rotate all secrets, API keys, tokens, and credentials on any system that installed axios 1.14.1/0.30.4, debug 4.4.2, chalk 5.6.1, any of the 17 co-compromised September 2025 ansi/color dependency-chain packages, or typo-crypto — treat the host as fully compromised and rotate from a clean device.
- Block network egress to sfrclak.com and 142.11.206.73:8000 at the perimeter, proxy, and EDR layer.
- Hunt for on-disk artifacts: %PROGRAMDATA%\wt.exe, %TEMP%\6202033.ps1, %TEMP%\6202033.vbs (Windows); /Library/Caches/com.apple.act.mond (macOS); /tmp/ld.py (Linux).
- Audit lockfiles across all repos for plain-crypto-js, proto-tinker-wc@0.1.87, and @depup/axios; purge and reinstall dependencies from a verified-clean registry snapshot.
Workarounds
- Pin dependency versions via lockfile with integrity hashes and disable automatic postinstall script execution until packages are verified against GHSA-3hfp-gqgh-xc5g, GHSA-fw8c-xr5c-95f9, and GHSA-2x9r-6wxq-hrr7.
Longer-term hardening
- Set npm config ignore-scripts=true in CI/build pipelines by default and explicitly allowlist packages that require postinstall execution.
- Require hardware-key (FIDO2/WebAuthn) 2FA for all package-maintainer and npm-publish-capable accounts; disable SMS/email-based 2FA fallback.
- Adopt continuous software-composition-analysis scanning (e.g., Socket, Aikido, Wiz) that flags new dependency versions before they reach build pipelines.
- Establish out-of-band, multi-channel verification for any maintainer trust-transfer event (co-maintainer additions, publish-access grants, 2FA resets), given this actor's documented use of fabricated video personas and cloned Slack/LinkedIn identities to build rapport before striking.
Weaknesses (CWE) in Amazon: North Korea's Sapphire Sleet (Stardust
Timeline of Amazon: North Korea's Sapphire Sleet (Stardust
Showing the 20 most recent tracked events.
- UNC1069/Sapphire Sleet begins seeding an estimated 1,700 malicious packages across npm, PyPI, Go, and Rust as part of a broad open-source supply-chain campaign (Amazon and Google/Mandiant reporting places the start 'since January 2025').
- typo-crypto npm package compromised — later described by Amazon CISO CJ Moses as a low-profile 'rehearsal' for the subsequent axios/debug/chalk operations.
- Phishing domain npmjs.help registered, three days ahead of the debug/chalk attack, to impersonate npm support.
- Maintainer acknowledged the debug/chalk compromise and began removing malicious versions roughly two hours after initial publication; ~2.6M downloads occurred during the exposure window and the payload reached an estimated 1 in 10 cloud environments.
- A second package, proto-tinker-wc@0.1.87, is detected compromised via the same phished account at 16:58 UTC.
- Aikido's threat-intel feed flags the compromised debug/chalk packages at 13:16 UTC, within roughly six minutes of the malicious publish.
- npm maintainer 'Qix' (debug, chalk, and 17 other packages) is phished via npmjs.help and loses control of the account; malicious versions of debug@4.4.2, chalk@5.6.1, and 17 dependency-chain packages are published, embedding a browser-side crypto-transaction hijacker targeting window.ethereum and Solana signing.
- Decoy package plain-crypto-js@4.2.0 is published, followed within hours by the malicious plain-crypto-js@4.2.1 dependency later used in the axios attack.
- npm removes the compromised axios and plain-crypto-js packages, closing a roughly three-hour exposure window (00:21-03:29 UTC).
- Elastic Security Labs files a GitHub Security Advisory for the compromised axios releases at approximately 01:50 UTC.
- axios@1.14.1 and axios@0.30.4 are published from the hijacked maintainer account 'jasonsaayman', each pulling in plain-crypto-js@4.2.1 to drop the WAVESHAPER.V2 cross-platform RAT via a SILKBELL postinstall dropper; a mirror package, @depup/axios, republishes the payload within 17 minutes.
- Microsoft publishes mitigation guidance for the axios npm supply-chain compromise and attributes the intrusion set to Sapphire Sleet.
- Google/Mandiant formally attributes the axios compromise to UNC1069; the Cloud Security Alliance publishes a research note on the AI-vendor npm code-signing risk exposed by the incident.
- CISA published an advisory on the axios npm supply-chain compromise.
- Additional detail on the Mastra scope compromise: a dormant maintainer account was used to inject typosquatted dependency easy-day-js@1.11.22 (impersonating dayjs) across 140+ packages via caret-range resolution during a 01:12-02:36 UTC window; the dropper disabled TLS validation, harvested credentials from 166 browser extensions (11 password managers, a Deloitte enterprise credential wallet, and Zapier), and Aikido linked it to the axios campaign via shared Hostwinds infrastructure and matching dropper tradecraft.
- Microsoft documents a related Sapphire Sleet postinstall-payload compromise of the Mastra AI npm package ecosystem, confirming continued campaign activity.
- npm v12 released, disabling dependency lifecycle (post-install) scripts by default — closing the axios/Mastra postinstall vector but not the underlying maintainer-credential-compromise entry point.
- npm began scanning newly published packages for malware; the scanning does not retroactively cover already-published packages such as typo-crypto@4.3.0, which remained installable.
- Amazon publicly links Sapphire Sleet/Stardust Chollima/UNC1069 to the typo-crypto, debug, chalk, and axios compromises as a single maintainer-trust-abuse campaign (CyberScoop reporting).
- The Hacker News and The Register published coverage of Amazon's attribution, noting the roughly 10-16 month gap between the original incidents and public actor attribution, and that Amazon's evidence chain does not explicitly map which indicator ties to which incident.
Update history for TL-2026-1760
- 2026-07-31 — North Korea's Sapphire Sleet Linked to axios, debug, chalk, typo-crypto npm Supply Chain Attacks: What changed No severity/exploitability/status escalation — all remain CRITICAL/ACTIVE/ACTIVE and attribution confidence remains MEDIUM. This is a pure intelligence-enrichment update: one new CWE, 28 new IOCs (concentrated in the previously
Sources cited for Amazon: North Korea's Sapphire Sleet (Stardust
- Amazon links North Korea to string of open-source software attacks
- Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
- N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust
- Inside the Axios supply chain compromise - one RAT to rule them all
- Supply Chain Attack on Axios Pulls Malicious Dependency
- axios Compromised on npm - Malicious Versions Drop Remote Access Trojan
- Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond
- chalk, debug and color on npm compromised in new supply chain attack
- npm debug and chalk packages compromised
- Mitigating the Axios npm supply chain compromise
- From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
- Axios supply chain attack - GitHub Security Advisory GHSA-3hfp-gqgh-xc5g
- Malware in plain-crypto-js - GitHub Security Advisory GHSA-2x9r-6wxq-hrr7
- Embedded Malicious Code via compromised maintainer account - GHSA-fw8c-xr5c-95f9
- [SECURITY] axios@1.14.1 compromised - contains malicious dependency plain-crypto-js
Detection coverage for TL-2026-1760
As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1760 across Splunk SPL, Microsoft KQL and Sigma, covering 58 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1760
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.