Amazon Ties Debug and Chalk NPM Hijacks to North Korean Hackers

A pair of hijacked packages on the npm registry turned into a reminder of how fragile the JavaScript supply chain really is. Amazon publicly attributed the takeover of the widely used debug and chalk packages to a North Korean threat actor it tracks as Sapphire Sleet, grouping the incident in with a broader campaign of […]