The September 2025 hijack of the npm packages debug and chalk was tied to North Korea This article explores attributed axios unc1069. . The same group planted a trojanized file in a small package called typo-crypto in March 2025, according to Amazon.

Amazon's attribution spans four named packages across three campaigns in twelve months. All three, it says, began the same way: socially engineer a trusted maintainer, then publish an update. them. The original Aikido and Wiz reports did not attribute the incident to North Korean.

Google independently attributed axios to UNC1069, citing the WAVESHAPER.V2 backdoor and an AstrillVPN node the group had used before.

Microsoft attributed the same compromise to Sapphire Sleet, which it says overlaps with activity other vendors track as UNC 1069, STARDUST CHOLLIMA, BlueNoroff, Alluring Pisces, CageyChameleon and CryptoCore. Aikido, which detected the September 2025 compromise, disputes that Amazon is the only source for the link. Aikido cited command-and-control overlap between the axios and Mastra attacks.

It described the debug and chalk compromise as "classic DPRK" in method and the link as "relatively clear" Amazon lists the SHA256 of core.js as the package hash, and its stated core.JS hash appears in no file in the tarball. Either a mislabeled indicator or a hash from a different copy would account for it. It does not close the maintainer-compromise path behind debug, chalk and axios.

The company told ZeroOwl it has tied that attack to North Korea for some time, in blog posts, conference talks and podcasts, and that the connection is common knowledge in the supply chain community.