Command Palette
Search for a command to run...

Amazon Links North Korean Hackers to Four Open-Source Software Compromises Since March 2025

techcybersecurityworldnorth-korea 3 posts · 3 accounts

A North Korean hacking group planted malicious code in the typo-crypto package in March 2025 to rehearse broader supply chain attacks, according to Amazon security researchers. The group later compromised the axios software library and two other open-source programs, targeting four packages in total over more than a year.

Researchers traced the connection by following domain records linked to the axios breach to earlier infrastructure. The attackers exploited trusted maintainer access to hide code within the packages, expanding the known scope of North Korean efforts to infiltrate software development environments.

From the sources (3 posts)

@tweetthreatnews

Amazon researchers say a North Korea-linked group used tiny typo-crypto as a rehearsal before compromising axios and other open-source packages, using trusted maintainer access and hidden code. #NorthKorea #axios #typo-crypto

@cyberscoopnews

Amazon’s security researchers say a hacking group tied to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet’s most widely used programming tools. The company’s threat intelli

@ddimolfetta

North Korea-linked hackers has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the known scope of DPRK’s efforts to access trusted code environments h

Preview built on a synthetic news corpus (16 weeks, Apr–Jul 2026). Impact calls are model reads, not price data.

About Archive