Amazon uncovers broad North Korean hacking campaign against open-source software
12 Articles
12 Articles
North Korea's Latest Cyber Campaign Puts Open-Source Software Supply Chain at Risk
A DPRK-linked threat actor has been tied to four separate compromises of widely used JavaScript libraries since March 2025, in a financially motivated campaign that exposed millions of software environments to malicious code.
North Korean hackers expand open-source software supply chain attacks: Amazon
North Korean cybercriminals are increasingly moving beyond direct intrusions into targeted networks by compromising open-source software libraries that underpin applications used worldwide, according to new research from Amazon. In a report published Wednesday, Amazon Threat Intelligence linked the North Korean threat actor Sapphire Sleet to the compromises of the popular software libraries Axios, Debug, Chalk […]
On the 30th, the government and the security industry released a "Joint Cyber Security Advisory," warning of a series of attacks by hacking organizations suspected of being backed by North Korea. These hacking groups have been distributing phishing emails disguised as resumes or job offers, while also employing "watering hole" tactics to infect visitors by hacking legitimate websites, such as news sites and hospitals. Special caution is required…
Suspicion of North Korea's Lazarus... Waterhole attacks carried out multiple times in the first half of the year. Spreading to phishing emails and corporate blackmail... Urging for the latest security updates. Hacking groups known to be supported by states, including North Korea, are sending phishing emails disguised as recruitment or donation offers, as well as to news and hospital sites.
A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon’s security researchers say a hacking group tied to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet’s most widely used programming tools. The company’s threat intelligence team said Wednesday at a media roundtable at its Arlington, Va., offices that the same group linked to the recent compromise of the open-source axios software library also planted malicious code in a pack…
Coverage Details
Bias Distribution
- 62% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









