Amazon links npm package hijack targeting debug and chalk to North Korean group
Amazon’s security team has attributed the hijacking of the popular npm packages 'debug' and 'chalk' to the North Korean threat actor Sapphire Sleet. The attackers compromised these widely used JavaScript libraries to inject malicious code, potentially affecting numerous applications. This incident highlights ongoing supply chain risks from state-sponsored hackers targeting open-source ecosystems.