Amazon Links North Korean Hackers to Four Open-Source Software Compromises Since March 2025
A North Korean hacking group planted malicious code in the typo-crypto package in March 2025 to rehearse broader supply chain attacks, according to Amazon security researchers. The group later compromised the axios software library and two other open-source programs, targeting four packages in total over more than a year.
Researchers traced the connection by following domain records linked to the axios breach to earlier infrastructure. The attackers exploited trusted maintainer access to hide code within the packages, expanding the known scope of North Korean efforts to infiltrate software development environments.
From the sources (3 posts)
@tweetthreatnewsAmazon researchers say a North Korea-linked group used tiny typo-crypto as a rehearsal before compromising axios and other open-source packages, using trusted maintainer access and hidden code. #NorthKorea #axios #typo-crypto
@cyberscoopnewsAmazon’s security researchers say a hacking group tied to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet’s most widely used programming tools. The company’s threat intelli
@ddimolfettaNorth Korea-linked hackers has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the known scope of DPRK’s efforts to access trusted code environments h