As cited
Copy frozen at (site build).
threat intel
North Korean hackers behind major open-source supply chain attacks, Amazon says
Amazon security researchers attributed multiple compromises of widely-used open-source software libraries to a North Korea-linked hacker group. The attacks targeted dependencies relied upon by developers across the globe to inject malicious code into downstream projects and applications.
Why it matters: Software developers and organizations using open-source dependencies are exposed to supply chain compromise; practitioners should review their dependency management and monitoring practices to detect similar attacks.
- Source published
- First seen by Cybersecurity Tracker