FAULT LINES
Signals That Move Strategy
Tech Frontiers · Americas · Cyber

Amazon Links North Korea to Four Open-Source Supply Chain Attacks Since March 2025

Amazon Threat Intelligence attributed four open-source JavaScript package compromises—typo-crypto, debug, chalk, and axios—to a single North Korean hacking group with medium confidence, based on reused code and attack pattern similarities. The axios package alone receives over 100 million weekly downloads.
AI synthesis, editor-reviewed · 1 source · July 29, 2026
Photo: Defense One

The medium-confidence attribution matters because it's Amazon making the call, not a boutique threat-intel shop: AWS hosts a plurality of the world's CI/CD infrastructure, which gives them telemetry on which packages actually get pulled into production builds at scale. If they're connecting these four incidents, they're seeing behavioral patterns in how the compromised packages were used post-deployment—not just static code similarities.

The fifteen-month campaign timeline (March 2025 to present) overlaps with the XZ Utils backdoor discovery in 2024, which means Pyongyang watched that playbook succeed and industrialized it.

WHY IT MATTERS

The attribution consolidates what looked like isolated incidents into a sustained campaign, which changes the threat model for every enterprise using automated dependency updates: a single actor has demonstrated repeatable access to the maintainer tier across multiple high-traffic packages.

The axios compromise alone put North Korean code inside the CI/CD pipelines of thousands of organizations configured for automatic updates—and Amazon's findings suggest three earlier breaches followed the same playbook, meaning the exposure window extends back fifteen months. Watch whether npm and GitHub implement maintainer verification requirements in Q4 2026; if they don't, the next compromise is a when, not an if.

WHAT THIS DOESN’T TELL US

Which specific versions of typo-crypto, debug, and chalk contained the malicious code, and what was the download count during the compromise windows?

Sources: Defense One
LinkedInX

Fault Lines

Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.

Front page → Get the weekly brief →