아마존, npm 패키지 해킹을 북한의 사이프리 슬리트와 연결지음.
아마존은 2025년 9월 npm 패키지인 debug와 chalk의 해킹 사건을 북한과 연결지었다. 이 사건은 10개월 동안 암호화폐 절도로 기록되어 있었으며, 유지 관리자가 유사한 npm 도메인을 통해 피싱에 당하고, 지갑을 소모시키는 스크립트가 18개 이상의 패키지에 삽입되었다. 이 패키지들은 주간 20억 이상의 다운로드를 기록하고 있었다.
Amazon links npm package hijack to North Korea's Sapphire Sleet.
Amazon has attributed the September 2025 hijacking of the npm packages debug and chalk to North Korea. For ten months, this incident was recorded as crypto theft, where a maintainer was phished through a lookalike npm domain, and a wallet-draining script was pushed into at least 18 packages. Collectively, these packages accounted for more than 2 billion downloads weekly.