|
News North Korean hackers expand open-source software supply chain attacks: AmazonResearchers link DPRK group to attacks on four popular JavaScript libraries underpinning software development worldwide North Korean cybercriminals are increasingly moving beyond direct intrusions into targeted networks by compromising open-source software libraries that underpin applications used worldwide, according to new research from Amazon. In a report published Wednesday, Amazon Threat Intelligence linked the North Korean threat actor Sapphire Sleet to the compromises of the popular software libraries Axios, Debug, Chalk and Typo-crypto. While the Axios attack was previously linked to North Korean actors, this is the first time the other three incidents have been publicly attributed to the group. The assessment made with “medium confidence” was based on shared technical © Korea Risk Group. All rights reserved. |



