← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 29, 2026 · 21:00via AWS Security Blog

Amazon identifies North Korean hacker group behind open-source supply chain attacks

Brief

Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications.

Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems.

We’re sharing this research to help the open source community and security teams better identify and address these types of events.

Read more on AWS Security Blog