North Korean Hackers Target Open Source Software Libraries

North Korean Hackers Target Open Source Software Libraries

First seen 29 Jul 2026, 23:26 UTC Aws.AmazonCyberscoop 72% similarity 75.5

Article Content

Browse articles
ThreatCluster

Amazon's threat intelligence team has linked a North Korean hacker group to multiple compromises of popular open source software libraries, including axios, debug, chalk, and typo-crypto. The group, tracked under various names, exploited social engineering tactics to gain access to trusted maintainers, allowing them to publish malicious updates. The axios library, which has over 100 million weekly downloads, was compromised in March 2026, following earlier attacks on smaller packages like typo-crypto in March 2025. The malicious code in typo-crypto was designed to evade detection by AI-based tools. This incident highlights the increasing sophistication and volume of software supply chain attacks attributed to DPRK-linked actors. Organizations relying on these libraries are at risk, as the compromised packages could affect countless applications globally.

Key Points: • North Korean hackers compromised multiple open source libraries, including axios and typo-crypto. • The attack method involved social engineering trusted maintainers to publish malicious updates. • The axios library alone is downloaded over 100 million times weekly, amplifying the potential impact.

ThreatCluster AI How this analysis works

Timeline

2025-03-01
Compromise of typo-crypto package
Malicious code was inserted into the typo-crypto package, serving as a rehearsal for future attacks.
Cyberscoop
2025-09-01
Compromise of debug and chalk packages
The same North Korean group compromised the debug and chalk libraries, expanding their attack vector.
Cyberscoop
2026-03-01
Compromise of axios package
The axios library, widely used with over 100 million downloads weekly, was compromised using similar tactics.
Aws.Amazon
2026-07-29
Amazon reveals DPRK-linked attacks
Amazon's threat intelligence team publicly linked the recent compromises to a North Korean hacker group.
Aws.Amazon

Community

Browse all →