debug
Coverage of debug in the Nexus archive.
- Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has linked the September 2025 npm package hijack of debug and chalk to North Korea’s Sapphire Sleet. The incident involved a phished maintainer via a lookalike npm domain and a wallet-draining script in 18 packages with over 2 billion weekly downloads. Earlier reports did not attribute the attack to a nation-state.
- A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon's security researchers revealed that a North Korea-linked hacking group targeted small npm packages like typo-crypto, debug, and chalk as a rehearsal before attacking the widely used axios library. The group used trusted maintainers to publish malicious updates, testing methods that later scaled to larger software. The typo-crypto attack in March 2025 involved a malicious file that activated with a specific numeric input and downloaded platform-specific code.