Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
4 Articles
4 Articles
'Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks
Amazon links multiple software supply chain attacks to one North Korean hacking group Generative AI enables convincing malware hidden inside trusted software packages at scale Attackers manipulated trusted maintainers before distributing compromised software updates to developers Amazon has linked a North Korean threat actor to several recent compromises of popular NPM software libraries. A report from Amazon Threat Intelligence connected recent…
N. Korea Group Behind Multiple Open Source Supply-Chain Attacks: Amazon
Amazon’s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing use of generative AI by bad actors and targeting of code repositories to financially focused attacks by nation-state hackers and the abuse of trust by development teams. It also is the latest report to point to the group – …
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open‑source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open‑source antivirus engine maintained by the Cisco Talos team, designed for mail gateways, file scanning, and general ma…
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts. This article has been indexed from eSecurity Planet Read the original article: Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet The post Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet appeared first on IT Security News.
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium

