Home Content News Amazon Exposes North Korean Attacks On Open Source Software

Amazon Exposes North Korean Attacks On Open Source Software

0
1

Amazon says a North Korea-linked hacking group compromised four widely used open-source JavaScript packages, exposing how trusted software supply chains are increasingly being exploited to reach thousands of downstream systems.

Amazon Threat Intelligence has linked a North Korea-backed hacking group to the compromise of four major open-source JavaScript packages dating back to March 2025, significantly expanding the publicly known scope of Pyongyang’s attacks on the open-source software ecosystem. The campaigns targeted typo-crypto, debug, chalk and axios, with the latter alone recording more than 100 million downloads each week.

According to Amazon, attackers infiltrated trusted open-source projects by compromising maintainers and publishing malicious updates. Organisations configured to automatically download package updates could have unknowingly introduced malware into their environments, allowing attackers to reach thousands of downstream systems through a single supply-chain compromise. Amazon attributed all four incidents to the same threat actor with medium confidence based on reused code, similar attack techniques and technical overlaps.

“One successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions,” said CJ Moses, Amazon Integrated Security CISO.

Amazon also warned that the attacks are becoming more sophisticated. Malicious functionality is now split across multiple packages, making individual components appear harmless during review. The company added that AI is helping attackers generate convincing code, documentation and fake developer identities, while also enabling package hallucination attacks that exploit AI coding assistants.

“Quite frankly, the open-source community is looking for good citizens because these packages are often not maintained by people who are getting paid to do that as a full-time job,” said Rick Anthony, Senior Manager for Amazon Inspector Vulnerability Management Service.

The findings reinforce growing concerns over securing open-source software, which underpins operating systems, web servers, encryption tools and enterprise applications.

LEAVE A REPLY

Please enter your comment!
Please enter your name here