ctipilot.ch

Sapphire Sleet

actor · actor:sapphire-sleet

DPRK-linked cluster that Amazon Threat Intelligence assesses with medium confidence — on the basis of command-and-control indicators and TTPs — to be behind the September 2025 compromises of the npm packages debug and chalk and the March 2026 compromise of axios, in each case obtaining publishing access by socially engineering a trusted package maintainer rather than exploiting a registry flaw. Amazon further assesses that a small March 2025 compromise of a package named typo-crypto — into which the actor committed a trojanised file that detonated only on a specific input value and then fetched an operating-system-appropriate second stage — was a testing ground for those later, higher-impact supply-chain operations. The attribution is Amazon's own medium-confidence assessment and has not been independently corroborated by another vendor; the alias UNC1069 is sourced to CyberScoop's reporting on Amazon's media roundtable rather than to Amazon's own publication (AWS Security Blog, CyberScoop, 2026-07-29).

Aliases: STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, Alluring Pisces, UNC1069

Coverage timeline
6
first 2026-05-29 → last 2026-07-30
Peak priority
high
1 high · 5 notable
Sources cited
14
14 hosts
Sections touched
5
research, updates, weekly-looking-ahead
Co-occurring entities
1
see Related entities below
ATT&CK techniques
8
pinned v19.1 · see below
2026-05-296 appearances2026-07-30

ATT&CK techniques

8 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×2

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · ATT&CK page ↗

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

Persistence TA0003

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1543.001Create or Modify System Process: Launch Agent×1

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

Privilege Escalation TA0004

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

T1543.001Create or Modify System Process: Launch Agent×1

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · ATT&CK page ↗

Credential Access TA0006

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-05-29/wiz-cirt-names-jinx-0164-linkedin-recruiter-lures-audiofix-m · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · ATT&CK page ↗

Story timeline

  1. 2026-07-30Amazon attributes the axios, debug and chalk npm compromises to a DPRK-linked cluster with medium confidence, and names a small 2025 package compromise as the rehearsal
    researchAmazon Threat Intelligence traces three major npm compromises to one DPRK-linked actor, and describes a payload that only detonates on a specific input
  2. 2026-06-29npm supply-chain worms — a sustained wave across the week
    weekly-multi-day
  3. 2026-06-22Threat actor: DPRK Sapphire Sleet escalates npm supply-chain attacks with the Mastra compromise
    weekly-research
  4. 2026-06-22Looking ahead — 2026-W25
    weekly-looking-ahead
  5. 2026-06-21Mastra npm scope compromise attributed to North Korea, with the access vector our deep dive could not name
    updates
  6. 2026-05-29Wiz CIRT names JINX-0164 — LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
    research

Where this entity is cited

  • research2
  • updates1
  • weekly-looking-ahead1
  • weekly-research1
  • weekly-multi-day1

Source distribution

  • aws.amazon.com1 (7%)
  • bleepingcomputer.com1 (7%)
  • cyberscoop.com1 (7%)
  • edpb.europa.eu1 (7%)
  • enisa.europa.eu1 (7%)
  • microsoft.com1 (7%)
  • msrc.microsoft.com1 (7%)
  • research.jfrog.com1 (7%)
  • other6 (43%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (14)

Entries about Sapphire Sleet (6)

2026-07-30 · view entry permalink →

NOTABLENATOB2

Amazon attributes the axios, debug and chalk npm compromises to a DPRK-linked cluster with medium confidence, and names a small 2025 package compromise as the rehearsal

Amazon's threat-intelligence team published an attribution assessment on 2026-07-29 linking three separate npm package compromises to one actor. The load-bearing sentence carries its own hedge, and it should be read with the hedge intact: "based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces" (AWS Security Blog, 2026-07-29). CyberScoop notes that researchers also track this cluster as UNC1069 (CyberScoop, 2026-07-29). Medium confidence is not attribution-by-consensus. Amazon is also precise about which part is new: it states that "while the axios compromise has been publicly attributed to this DPRK-linked threat actor, the typo-crypto, debug, and chalk incidents haven't previously been connected to it" (AWS Security Blog, 2026-07-29). For a defender the actor label changes little, but the tradecraft description below changes something real.

The compromises run from March 2025 to March 2026 and escalate in blast radius: debug and chalk in September 2025, then axios in March 2026, which Amazon describes as one of the most widely used JavaScript libraries at more than 100 million weekly downloads (AWS Security Blog, 2026-07-29). None of them involved breaking the registry. In Amazon's words, "in each case, the threat actor gained access by socially engineering a trusted maintainer of the package, then published a software update containing malicious code" (AWS Security Blog, 2026-07-29) — the trust chain held exactly as designed and delivered the malicious version, which is why provenance and signing controls do not help here.

The genuinely new element is the rehearsal. Amazon points at a March 2025 compromise of a package named typo-crypto, into which the actor committed a trojanised file that masqueraded as the unrelated legitimate core-js package, and assesses that "based on the limited number of observed downloads... this campaign was small scale and likely served as a testing ground for the more visible supply chain operations that followed in late 2025 and 2026" (AWS Security Blog, 2026-07-29). That is a patience pattern worth internalising: a package with negligible download counts is not necessarily a failed attack, it may be where the maintainer-social-engineering approach and the payload were refined before being pointed at something with a hundred million weekly installs.

Two mechanics from that rehearsal payload matter for anyone who triages suspicious dependencies. First, detonation was conditional on input rather than on time or environment: the trojanised file executed only when it received a hash input beginning with one specific literal value, and only then downloaded an operating-system-appropriate second stage, with behaviour tailored separately for Windows, macOS and Linux (AWS Security Blog, 2026-07-29). A package like that installs and runs cleanly in any sandbox that does not happen to feed it the trigger value, so "we installed it and nothing happened" is not a clean result. Second, the payload combined file-based persistence with payload rotation and layered obfuscation — base64-encoded text over an XOR cipher under a fixed key (AWS Security Blog, 2026-07-29) — so a static scan of the shipped file yields little without unwrapping those layers.

Amazon separately describes a shift in how these operations are structured, observing that attackers increasingly split one malicious workflow across several individually unremarkable packages, and that "this approach is designed to defeat scanners that evaluate packages one by one instead of reasoning about how they interact in a real dependency graph" (AWS Security Blog, 2026-07-29). Amazon frames that as an observation rather than advice, but the implication for a review process is direct: a per-package verdict is the wrong unit of analysis when the malicious behaviour only exists once the pieces are resolved together.

Triage: a benign minified or bundled dependency also carries base64 blobs and unreadable code, so obfuscation alone does not separate the two. The discriminators are behavioural and structural: a code path that stays inert unless a caller supplies a particular argument value, a second-stage fetch whose destination differs by host operating system, and persistence written outside the package's own installation tree. A dependency that reaches the network at all during a build or test run, when its documented function does not require it, is the anomaly worth pulling.

Based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces.

In each case, the threat actor gained access by socially engineering a trusted maintainer of the package, then published a software update containing malicious code.

Based on the limited number of observed downloads, Amazon Threat Intelligence assesses that this campaign was small scale and likely served as a testing ground for the more visible supply chain operations that followed in late 2025 and 2026.

This approach is designed to defeat scanners that evaluate packages one by one instead of reasoning about how they interact in a real dependency graph.

When triggered, it downloads a second-stage payload from a hardcoded C2 server, then executes the payload based on the victim's operating system, with behavior tailored for Windows, macOS, or Linux.

AWS Security Blog 2026-07-29
research30 Jul 05:00Zmulti-sourceOpen finding ↗

2026-06-29 · view entry permalink →

NOTABLE

npm supply-chain worms — a sustained wave across the week

Three separate npm-ecosystem supply-chain events were in play across the window, and the pattern is the story. Microsoft attributed the Mastra scope compromise (140+ @mastra packages, postinstall dropper) to North Korea's Sapphire Sleet (covered in the daily on 06-21). JFrog documented PostCSS typosquats from the abdrizak account delivering a Nuitka-compiled Python RAT with Chrome DPAPI credential theft. And on 2026-06-25 Socket reported a fresh Miasma / "Mini Shai-Hulud" worm wave across LeoPlatform/RStreams packages (carried in the daily 06-27), the self-propagating supply-chain worm last seen backdooring @redhat-cloud-services.

The synthesis: the npm registry is under continuous, parallel pressure from a state actor (DPRK), commodity typosquat crews and a self-replicating worm — three different operators, one ecosystem. The common control is the same one npm v12 is about to enforce by default: disable install scripts (--ignore-scripts), pin and review dependencies, and treat CI build-time package resolution as an attack surface. (daily 06-21, daily 06-24, daily 06-27)

synthesis29 Jun 00:20Zmulti-sourceOpen finding ↗

2026-06-22 · view entry permalink →

NOTABLE

Looking ahead — 2026-W25

A focused, justified list — items already in motion, not predictions.

  • RoguePlanet (CVE-2026-50656) has no patch and a PoC that works on June builds — watch MSRC for an out-of-band fix. Microsoft says a fix is "in development" with no timeline; the researcher warns mitigations are not reliable. Decide now whether to hold for July Patch Tuesday or push application allowlisting as an interim control. (MSRC; daily 06-19)
  • FortiBleed credential resets are not a one-and-done — expect more named victims and AD-persistence findings. CISA confirmed full AD domain takeover at multiple organisations; finish session termination, credential rotation and PBKDF2 migration, then hunt for post-compromise persistence rather than assuming the reset closed it. (SecurityWeek; daily 06-20)
  • ShinyHunters PeopleSoft notifications are still landing — more European victims are likely. Google GTIG has notified 100+ organisations (68% higher education); EU universities are a probable next-named class. Patch internet-reachable PeopleSoft and hunt the /PSEMHUB/ and /PSIGW/HttpListeningConnector paths. (daily 06-16)
  • CRA Single Reporting Platform go-live is ~82 days out (11 September). ENISA's access manual and a dry-run window are due now; in-scope manufacturers (including Swiss exporters to the EU) should register and wire the 24/72-hour reporting flow into their PSIRT process before the obligation binds. (ENISA SRP)
  • EDPB Article 33 harmonised-template consultation closes 5 August. Multi-jurisdiction breach-response owners have a window to review and comment before the EDPB sets a mandatory-adoption timeline. (EDPB)
  • npm v12 will disable install scripts by default — the Mastra compromise is this week's reminder to audit CI before the change. Sapphire Sleet's postinstall dropper is exactly the kill chain --ignore-scripts / npm v12 defaults neutralise; inventory pipelines that rely on build scripts now. (Microsoft; daily 06-21)
  • France's NIS2 transposition remains unresolved into late 2026. Organisations with French counterparts should track the next parliamentary session; NIS2-derived notification flows from French partners are not yet enforceable. (Viktoria Compliance)
outlook22 Jun 00:15Zmulti-sourceOpen finding ↗

Earlier coverage (3)