DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SAPPHIRE-SLEET-NPM-CHAINFIRST SEEN: 2017 (npm supply chain campaign: MAR 2025)

SAPPHIRE SLEET

ALSO KNOWN AS: BlueNoroff, Stardust Chollima, CageyChameleon, Alluring Pisces, UNC1069
FROM:DMZ INTELLIGENCE DESK
ORIGIN:North Korea (DPRK) — assessed as financially-motivated unit distinct from Lazarus Group
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2017 (npm supply chain campaign: MAR 2025)
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL85/100
RESOURCES93/100
PERSISTENCE93/100
STEALTH93/100
IMPACT85/100

Amazon Web Services Threat Intelligence publicly attributed a sustained npm supply-chain campaign to Sapphire Sleet on July 29, 2026, connecting four previously unlinked package compromises — typo-crypto (Mar 2025), debug and chalk (Sep 2025), axios (Mar 2026), and Mastra AI framework (Jun 2026) — to the same DPRK actor. The group socially engineers trusted open-source maintainers to publish trojanized updates containing post-install hooks that steal credentials and cryptocurrency wallets. This is the first time these compromises have been publicly unified under a single DPRK attribution.

Revenue generation for the DPRK regime via cryptocurrency theft and developer ecosystem compromise; sanctions circumvention

Social engineering of OSS package maintainers, trojanized npm packages, post-install hook abuse, cross-platform RAT deployment (Windows/macOS/Linux), cryptocurrency wallet harvesting (166 wallet extension IDs targeted), TLS certificate disabling, C2 via attacker-controlled infrastructure, code reuse across campaigns

SOFTWARE DEVELOPMENT
CRYPTOCURRENCY
AI/ML FRAMEWORKS
FINANCIAL SERVICES
OPEN SOURCE ECOSYSTEM

Attacker-controlled C2 domains registered via 2025 registrations; malicious npm registry accounts; post-install script droppers; cross-platform second-stage payloads; OSV record MAL-2026-3400 (typo-crypto@4.3.0)

FILE DATE: MAR 2025
typo-crypto Test Run
Sapphire Sleet poisoned the small typo-crypto npm package as an assessed test-run to refine their supply-chain tradecraft before targeting higher-volume packages.
FILE DATE: SEP 2025
debug & chalk Compromise
The group compromised the widely used debug and chalk npm packages ████████████████████ downloads), embedding malicious post-install hooks to achieve downstream developer access at scale.
FILE DATE: MAR 2026
Axios Supply Chain Attack
Sapphire Sleet socially engineered a maintainer of axios (100M+ weekly downloads) to publish a trojanized update containing a phantom dependency that downloaded a cross-platform RAT.
FILE DATE: JUN 2026
Mastra AI Framework Poisoning
In a 45-minute window on June 17, 2026, Sapphire Sleet compromised the 'ehindero' npm maintainer account and published 141 poisoned @mastra packages (8M weekly downloads) ██████████████████████ malicious dependency to harvest 166 crypto wallet browser extensions.
FILE DATE: JUL 2026
AWS Public Attribution — PolinRider Connection
On July 29, 2026, Amazon Threat Intelligence publicly unified all four npm compromises under Sapphire Sleet attribution, simultaneously disclosed alongside Socket/Rescana reporting linking DPRK groups to the broader PolinRider supply-chain campaign spanning npm, Packagist, Go modules, and Chrome Store (108 malicious packages).
SHARE BRIEF:✕ Post on Xin Share on LinkedIn