# Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign

> Amazon attributes, with medium confidence, a string of npm supply-chain compromises spanning March 2025-2026 to the North Korean state-linked cluster tracked as Sapphire Sleet, Stardust Chollima, and UNC1069. The actor cultivated trust with package maintainers to obtain publishing access, then shipped obfuscated multi-stage postinstall droppers that deployed the cross-platform WAVESHAPER.V2 RAT across affected packages including axios (100M+ weekly downloads), debug, chalk, and typo-crypto.

- **Published:** 2026-07-29T00:00:00Z
- **Last reviewed:** 2026-07-31T10:48:43.284Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1760
- **ID:** TL-2026-1760
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** APT38 (North Korea)
- **Detections:** 9 · **IOCs:** 58 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Amazon's threat-intelligence team (CISO CJ Moses, AWS Senior Engineering Manager Rick Anthony) links four npm supply-chain incidents into a single North Korean campaign: the March 2025 compromise of typo-crypto (described internally as a low-stakes 'rehearsal'), the September 2025 mass compromise of debug, chalk, and 17 dependency-chain packages (ansi-styles, color-convert, strip-ansi, wrap-ansi, and others), and the March 2026 compromise of axios, one of the most-downloaded JavaScript HTTP client libraries. Across all four, the actor did not exploit a technical vulnerability — it built social rapport with maintainers holding legitimate publish rights (via phishing emails impersonating npm support, and in parallel efforts, fabricated video personas and cloned Slack/LinkedIn identities), then abused that trust to push malicious releases.

The September 2025 wave began when maintainer 'Qix' was phished via the domain npmjs.help (registered just three days prior) and lost control of the npm account behind debug, chalk, and 17 other high-download packages. The malicious code was a browser-side interceptor that wrapped fetch/XMLHttpRequest and wallet-signing interfaces (window.ethereum.request, Solana signing) to silently rewrite transaction recipients, spender addresses, and ERC-20 allowances before user signature — a crypto-clipper targeting ETH, BTC, SOL, TRON, LTC, and BCH. Wiz found the malicious code reached roughly 10% of scanned cloud environments within a two-hour exposure window, out of ~99% of environments that carried the targeted packages at all.

The March 2026 axios compromise used a different payload architecture: the hijacked maintainer account ('jasonsaayman') published axios@1.14.1 and axios@0.30.4, each carrying a new transitive dependency, plain-crypto-js@4.2.1, that was not a real axios dependency. Its postinstall hook ran a two-layer-obfuscated (reversed-Base64 plus XOR, key OrDeR_7077) JavaScript dropper (tracked by Google/Mandiant as SILKBELL) that fingerprinted the OS and pulled a platform-specific second-stage payload from sfrclak.com:8000/6202033 — a PowerShell implant on Windows, a C++ Mach-O binary on macOS, and a Python backdoor on Linux — all instances of the WAVESHAPER.V2 remote-access trojan. WAVESHAPER.V2 beacons every 60 seconds over HTTP POST with Base64-encoded JSON, spoofing an Internet Explorer 8 User-Agent and a fake packages.npm.org domain string in its body to blend in with registry traffic; it supports kill, rundir (filesystem enumeration), runscript (PowerShell/AppleScript/Shell execution), and peinject (reflective binary injection) commands. The dropper is self-erasing: it deletes setup.js and swaps the poisoned package.json for a clean package.md, removing the postinstall-trigger evidence from node_modules. A mirror package, @depup/axios, republished the payload within 17 minutes of the original malicious release, and forensic build-path strings inside the macOS binary ('Jain_DEV/client_mac/macWebT/macWebT') tie the implant to BlueNoroff's prior 'webT' module used in the RustBucket and Hidden Risk campaigns (2023-2024).

Google/Mandiant formally attributed the axios compromise to UNC1069 (aliased Sapphire Sleet, Stardust Chollima, BlueNoroff, CryptoCore, CageyChameleon, APT38, TA444), an actor active since at least 2018/2020 whose primary historical targeting is the cryptocurrency, venture-capital, and blockchain sectors. Amazon assesses with medium confidence that the same actor sits behind all four incidents (typo-crypto, debug, chalk, axios), and separately reports the same cluster has seeded an estimated 1,700 malicious packages across npm, PyPI, Go, and Rust since January 2025 — a related June 2026 Microsoft report documents a further Sapphire Sleet postinstall-payload compromise of the Mastra AI npm ecosystem, indicating the campaign is ongoing.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1586 Compromise Accounts
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1070 Indicator Removal
- T1055 Process Injection
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1057 Process Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1132 Data Encoding
- T1565 Data Manipulation
- T1589 Gather Victim Identity Information
- T1591 Gather Victim Org Information
- T1587 Develop Capabilities
- T1543 Create or Modify System Process
- T1053 Scheduled Task/Job
- T1685 Disable or Modify Tools
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1518 Software Discovery
- T1568 Dynamic Resolution
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft

## Sources

- [Amazon links North Korea to string of open-source software attacks](https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/)
- [Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069](https://thehackernews.com/2026/04/google-attributes-axios-npm-supply.html)
- [N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust](https://thehackernews.com/2026/04/n-korean-hackers-spread-1700-malicious.html)
- [Inside the Axios supply chain compromise - one RAT to rule them all](https://www.elastic.co/security-labs/axios-one-rat-to-rule-them-all)
- [Supply Chain Attack on Axios Pulls Malicious Dependency](https://socket.dev/blog/axios-npm-package-compromised)
- [axios Compromised on npm - Malicious Versions Drop Remote Access Trojan](https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan)
- [Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk)
- [chalk, debug and color on npm compromised in new supply chain attack](https://semgrep.dev/blog/2025/chalk-debug-and-color-on-npm-compromised-in-new-supply-chain-attack/)
- [npm debug and chalk packages compromised](https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised)
- [Mitigating the Axios npm supply chain compromise](https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios-npm-supply-chain-compromise/)
- [From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet](https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/)
- [Axios supply chain attack - GitHub Security Advisory GHSA-3hfp-gqgh-xc5g](https://github.com/advisories/GHSA-3hfp-gqgh-xc5g)
- [Malware in plain-crypto-js - GitHub Security Advisory GHSA-2x9r-6wxq-hrr7](https://github.com/advisories/GHSA-2x9r-6wxq-hrr7)
- [Embedded Malicious Code via compromised maintainer account - GHSA-fw8c-xr5c-95f9](https://advisories.gitlab.com/npm/axios/GHSA-fw8c-xr5c-95f9/)
- [SECURITY axios@1.14.1 compromised - contains malicious dependency plain-crypto-js](https://github.com/axios/axios/issues/10630)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1760
