SAPPHIRE SLEET acquires typo-crypto
Acquisition Disputed 95% confidence first seen
The deal
typo-crypto Undisclosed Acquisition · announced 7 Aug 2026
Investors SAPPHIRE SLEET
Deal terms as reported in the coverage below.
Decision brief
- What changed
- Amazon's threat intelligence team attributed a North Korean threat actor (SAPPHIRE SLEET) to social-engineering compromises of NPM package maintainers, resulting in malicious updates published to widely used libraries including axios, debug, chalk, and typo-crypto.
- Why it matters
- Axios alone has over 100 million weekly downloads, so a compromise at the maintainer level can propagate malicious code into a massive number of downstream applications and environments nearly simultaneously. This highlights that open-source software supply chains remain a high-leverage attack vector for state-linked actors, and that social engineering targeting individual maintainers can bypass traditional technical defenses.
- Evidence
- The claim comes from a single source (The Neuron) reporting on attribution made by Amazon's threat intelligence team; no independent corroboration from other outlets is included in the provided coverage.
- What remains uncertain
- It is unclear how many organizations actually pulled the compromised package versions into production, what the specific malicious payload did, and whether other packages beyond those named were affected. The attribution to SAPPHIRE SLEET relies solely on Amazon's assessment as relayed by one outlet, so independent verification is unconfirmed.
- Monitor next
- Watch for follow-up disclosures from NPM, other security vendors, or affected package maintainers confirming the scope of compromise and any observed downstream exploitation.
Analytical support, not advice — assumptions and open questions stated above.