Amazon uncovers broad North Korean hacking campaign against open-source software

https://cdn.nextgov.com/media/img/cd/2026/07/29/072926NKoreaNG/open-graph.jpg

Matt Anderson Photography/Getty Images

ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW

July 29, 2026 02:58 PM ET

New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.

A North Korea-linked hacker group has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the publicly known scope of Pyongyang’s efforts to use trusted code to reach large numbers of potential victims and gain access to companies’ systems.

The assessment for the first time links the same financially-motivated hacking group to compromises of four major JavaScript packages — typo-crypto, debug, chalk and axios — that developers use as building blocks for other software. The axios package alone receives more than 100 million downloads each week, and its compromise had previously been attributed to the North Korean group.

...

Copyright of this story solely belongs to nextgov.com. To see the full text click HERE

Read more