SAPPHIRE SLEET acquires chalk
Acquisition Disputed 98% confidence first seen
The deal
chalk Undisclosed Acquisition · announced 7 Aug 2026
Investors SAPPHIRE SLEET
Deal terms as reported in the coverage below.
Decision brief
- What changed
- Amazon's threat intelligence team attributed a North Korean threat actor known as SAPPHIRE SLEET to the compromise of widely-used NPM JavaScript packages, including chalk, axios, debug, and typo-crypto, via social engineering to obtain maintainer access and publish malicious package updates.
- Why it matters
- Open-source supply chain compromises of this scale can silently propagate malicious code into thousands of downstream applications; axios alone has over 100 million weekly downloads, meaning exposure is likely widespread and hard to fully scope. Nation-state involvement raises the stakes beyond typical criminal supply-chain attacks, suggesting more sophisticated, persistent targeting of developer ecosystems.
- Evidence
- The claim comes from a single source (The Neuron) reporting on findings attributed to Amazon's threat intelligence team; no independent corroboration from other outlets is provided in this coverage.
- What remains uncertain
- It is unclear how many downstream organizations were actually compromised versus merely exposed to the malicious updates, what specific malicious behavior the packages executed, and whether other popular packages beyond those named were also affected. The attribution to SAPPHIRE SLEET and North Korea rests solely on Amazon's assessment as relayed by one outlet, without additional independent verification in this coverage.
- Monitor next
- Watch for official advisories or CVEs from NPM, the affected package maintainers, or additional threat intelligence firms confirming scope, affected versions, and remediation guidance.
Analytical support, not advice — assumptions and open questions stated above.