Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign — Threadlinqs Intelligence
As of 2026-07-31, Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign is a critical-severity supply chain threat attributed to Sapphire Sleet (UNC1069 (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 58 indicators of compromise.
Threat ID: TL-2026-1760 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Updated: 2026-07-31 · revalidated 1× · latest source
Attribution: Sapphire Sleet (UNC1069 · North Korea (DPRK) · FINANCIAL
Amazon attributes, with medium confidence, a string of npm supply-chain compromises spanning March 2025-2026 to the North Korean state-linked cluster tracked as Sapphire Sleet, Stardust Chollima, and
Amazon's threat-intelligence team (CISO CJ Moses, AWS Senior Engineering Manager Rick Anthony) links four npm supply-chain incidents into a single North Korean campaign: the March 2025 compromise of typo-crypto (described internally as a low-stakes 'rehearsal'), the September 2025 mass compromise of debug, chalk, and 17 dependency-chain packages (ansi-styles, color-convert, strip-ansi, wrap-ansi, and others), and the March 2026 compromise of axios, one of the most-downloaded JavaScript HTTP client libraries. Across all four, the actor did not exploit a technical vulnerability — it built social rapport with maintainers holding legitimate publish rights (via phishing emails impersonating npm support, and in parallel efforts, fabricated video personas and cloned Slack/LinkedIn identities), then abused that trust to push malicious releases.
The September 2025 wave began when maintainer 'Qix' was phished via the domain npmjs.help (registered just three days prior) and lost control of the npm account behind debug, chalk, and 17 other high-download packages. The malicious code was a browser-side interceptor that wrapped fetch/XMLHttpRequest and wallet-signing interfaces (window.ethereum.request, Solana signing) to silently rewrite transaction recipients, spender addresses, and ERC-20 allowances before user signature — a crypto-clipper targeting ETH, BTC, SOL, TRON, LTC, and BCH. Wiz found the malicious code reached roughly 10% of scanned cloud environments within a two-hour exposure window, out of ~99% of environments that carried the targeted packages at all.
The March 2026 axios compromise used a different payload architecture: the hijacked maintainer account ('jasonsaayman') published axios@1.14.1 and axios@0.30.4, each carrying a new transitive dependency, plain-crypto-js@4.2.1, that was not a real axios dependency. Its postinstall hook ran a two-layer-obfuscated (reversed-Base64 plus XOR, key OrDeR_7077) JavaScript dropper (tracked by Google/Mandiant as SILKBELL) that fingerprinted the OS and pulled a platform-specific second-stage payload from sfrclak.com:8000/6202033 — a PowerShell implant on Windows, a C++ Mach-O binary on macOS, and a Python backdoor on Linux — all instances of the WAVESHAPER.V2 remote-access trojan. WAVESHAPER.V2 beacons every 60 seconds over HTTP POST with Base64-encoded JSON, spoofing an Internet Explorer 8 User-Agent and a fake packages.npm.org domain string in its body to blend in with registry traffic; it supports kill, rundir (filesystem enumeration), runscript (PowerShell/AppleScript/Shell execution), and peinject (reflective binary injection) commands. The dropper is self-erasing: it deletes setup.js and swaps the poisoned package.json for a clean package.md, removing the postinstall-trigger evidence from node_modules. A mirror package, @depup/axios, republished the payload within 17 minutes of the original malicious release, and forensic build-path strings inside the macOS binary ('Jain_DEV/client_mac/macWebT/macWebT') tie the implant to BlueNoroff's prior 'webT' module used in the RustBucket and Hidden Risk campaigns (2023-2024).
Google/Mandiant formally attributed the axios compromise to UNC1069 (aliased Sapphire Sleet, Stardust Chollima, BlueNoroff, CryptoCore, CageyChameleon, APT38, TA444), an actor active since at least 2018/2020 whose primary historical targeting is the cryptocurrency, venture-capital, and blockchain sectors. Amazon assesses with medium confidence that the same actor sits behind all four incidents (typo-crypto, debug, chalk, axios), and separately reports the same cluster has seeded an estimated 1,700 malicious packages across npm, PyPI, Go, and Rust since January 2025 — a related June 2026 Microsoft report documents a further Sapphire Sleet postinstall-payload compromise of the Mastra AI npm ecosystem, indicating the campaign is ongoing.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494
Target sectors: technology, software-development, cryptocurrency, financial-services, venture-capital, blockchain, cloud-computing
Target regions: Global
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 58 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1583, T1585, T1586, T1608, T1195, T1566, T1059, T1547, T1027, T1140