{"id":4724,"date":"2026-08-03T21:16:23","date_gmt":"2026-08-03T21:16:23","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/03\/n-korea-group-behind-multiple-open-source-supply-chain-attacks-amazon\/"},"modified":"2026-08-03T21:16:23","modified_gmt":"2026-08-03T21:16:23","slug":"n-korea-group-behind-multiple-open-source-supply-chain-attacks-amazon","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/03\/n-korea-group-behind-multiple-open-source-supply-chain-attacks-amazon\/","title":{"rendered":"N. Korea Group Behind Multiple Open Source Supply-Chain Attacks: Amazon"},"content":{"rendered":"<div><img data-opt-id=1361848722  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/08\/north-korea-open-source-supply-chain-770x330-1.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=226860401  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/08\/north-korea-open-source-supply-chain-770x330-1-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>Amazon\u2019s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing use of generative AI by bad actors and targeting of code repositories to financially focused attacks by nation-state hackers and the abuse of trust by development teams.<\/p>\n<p>It also is the latest report to point to the group \u2013 known by such names as Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces \u2013 linked to the Democratic People\u2019s Republic of Korea (DPRK) to supply chain attacks over the past couple of years that involve placing malicious code into packages in the npm repository.<\/p>\n<p>\u201cWhen an attacker compromises a widely used open source package, every organization that depends on that package is potentially affected,\u201d CJ Moses, CISO of Amazon Integrated Security, <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks\/\" target=\"_blank\" rel=\"noopener\">wrote in the report<\/a>, adding that they have \u201cobserved the volume and sophistication of software supply chain attacks increase, driven in large part by DPRK\u2011linked threat actors and cybercriminal groups.\u201d<\/p>\n<p>Supply chain attacks are increasingly popular because groups that compromise a small number of popular packages can gain access to thousands of downstream operations at the same time, a more efficient process than targeting organizations individually, Moses wrote.<\/p>\n<h3>North Korea and Package Compromises<\/h3>\n<p>Others are seeing similar trends. Socket researchers in March noted that the North Korean-linked Famous Chollima \u2013 the nation-state actor behind the <a href=\"https:\/\/securityboulevard.com\/2025\/04\/north-korean-group-creates-fake-crypto-firms-in-job-complex-scam\/?__hstc=48761529.62562598e66181ffaa14612382b677c7.1756476334428.1785692369307.1785771989659.92&amp;__hssc=48761529.4.1785771989659&amp;__hsfp=10b49dc2b5a95ac0fe6d2c7a80438bec\" target=\"_blank\" rel=\"noopener\">long-running Contagious Interview scam<\/a> \u2013 was using dozens of malicious npm packages to <a href=\"https:\/\/devops.com\/n-korean-famous-chollima-hackers-use-malicious-npm-packages-to-steal-data\/\" target=\"_blank\" rel=\"noopener\">steal credentials and secrets<\/a> from developers. GitHub earlier this year said that in 2025, it <a href=\"https:\/\/about.gitlab.com\/blog\/gitlab-threat-intelligence-reveals-north-korean-tradecraft\/\" target=\"_blank\" rel=\"noopener\">banned an average of 11 accounts<\/a> each month for distributing malware or loaders linked to DPRK-linked threat groups.<\/p>\n<p>A researcher from Pusan National University in South Korea wrote in a report in March that North Korea\u2019s cyber operations are now \u201ca <a href=\"https:\/\/jfsdigital.org\/from-lazarus-to-leviathan-a-foresight-analysis-of-north-koreas-cyber-operations-and-its-implications\/\" target=\"_blank\" rel=\"noopener\">central pillar<\/a> of its asymmetric national strategy and survival logic.\u201d<\/p>\n<p>\u201cFacing chronic resource shortages, diplomatic isolation, and sustained sanctions, the regime has increasingly turned to cybercrime, espionage, and digital disruption to sustain both its economy and strategic leverage,\u201d the researcher wrote. \u201cThese operations \u2026 illustrate a form of asymmetric power projection in which code, rather than conventional force, is weaponized to offset economic weakness and international marginalization.\u201d<\/p>\n<h3>A Consistent Drumbeat<\/h3>\n<p>Amazon\u2019s Moses wrote that in March 2025, the North Korean group compromised the npm typo-crypto package, and followed that in September 2025 by abusing the debug and chalk packages. In March, the group <a href=\"https:\/\/devops.com\/north-korean-hackers-suspected-in-supply-chain-attack-on-popular-axios-project\/\" target=\"_blank\" rel=\"noopener\">compromised the axios package<\/a>, a popular JavaScript library that is downloaded 100 million times a week.<\/p>\n<p>It\u2019s the first time researchers have linked all three attacks to the single North Korean group.<\/p>\n<p>The attacks are the same in each case. The threat actor uses social engineering techniques against the maintainer of the package, and then publishes a software update that includes malicious code. When an organization automatically pulls in the latest version of the packages, they also bring in the malicious code. The typo-crypto compromise was relatively small, suggesting the group was using it as a testing ground for future operations, according to Moses.<\/p>\n<p>Microsoft in April <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/04\/01\/mitigating-the-axios-npm-supply-chain-compromise\/\" target=\"_blank\" rel=\"noopener\">attributed the axios campaign<\/a> to Sapphire Sleet. Days earlier, Google Threat Intelligence Group <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/north-korea-threat-actor-targets-axios-npm-package\" target=\"_blank\" rel=\"noopener\">pointed to a North Korean group<\/a>, UNC1069, as the culprit. UNC1069 is the same threat cluster as Sapphire Sleet. Wiz found that about <a href=\"https:\/\/www.wiz.io\/blog\/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debug-chalk\" target=\"_blank\" rel=\"noopener\">one in 10 cloud environments<\/a> were impacted by the debug and chalk compromises during a two-hour timeframe.<\/p>\n<h3>Threat Groups Evolve Their Operations<\/h3>\n<p>Moses noted that the package compromises are illustrative of the evolving nature of attackers\u2019 tradecraft. The shifts include bad actors splitting a single malicious workflow across multiple ordinary packages as a way of hiding the threat, which only becomes evident when the components are inadvertently put back together in particular sequences.<\/p>\n<p>They also take the time to establish \u2013 and then abuse \u2013 the trust that developers put into open source packages. They\u2019ll publish and maintain useful packages for months to gain confidence among developers, then introduce malware once their packages become popular.<\/p>\n<p>In addition, multi-stage payloads are using strong cryptographic techniques rather than just obfuscation, payloads don\u2019t launch within sandboxes, and generative AI is increasingly being used to generate code and scale their campaigns.<\/p>\n<p>\u201cGenerative AI is changing what attackers can produce and what defenders can rely on,\u201d the Amazon researchers wrote. \u201cHistorically, many malicious packages were caught because they looked wrong, with broken language, thin documentation, obvious copy-paste, or a telltale function reused across samples. Generative AI erases many of those signals.\u201d<\/p>\n<h3>Developers, Packages Under Attack<\/h3>\n<p>Software engineers are increasingly attractive targets for bad actors.<\/p>\n<p>\u201cDevelopers hold cloud credentials, npm publish tokens, and direct access to source code, and their work requires installing packages and running third-party code on their workstations,\u201d Wiz researchers <a href=\"https:\/\/www.wiz.io\/blog\/introducing-the-wiz-sensor-for-developer-workstations\">wrote<\/a>. \u201cAI coding agents now do the same at machine speed. As AI expands who builds software, others are joining that group, each pulling packages, IDE extensions, and AI tools onto workstations that reach directly into cloud environments and deployment pipelines.\u201d<\/p>\n<p>Open repositories are in the crosshairs because they\u2019re trusted by the community, are often automatically updated, and are maintained by communities that encourage new contributors to their projects, according to Moses.<\/p>\n<p><a href=\"https:\/\/devops.com\/n-korea-group-behind-multiple-open-source-supply-chain-attacks-amazon\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Amazon\u2019s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4725,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4724","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4724"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4724\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4725"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}