Amazon identifies North Korean hacker group behind open-source supply chain attacks
ID: 008d375c-015d-5f61-ae5f-885d01a968b9
STIX ID: report--008d375c-015d-5f61-ae5f-885d01a968b9
Feed Name: AWS Security Blog
Amazon Threat Intelligence links multiple high-impact NPM supply‑chain compromises (typo-crypto, debug, chalk, and axios) to a DPRK‑linked threat actor, describing social‑engineering of maintainers to publish trojanized packages that execute multi-stage, obfuscated payloads delivered from hardcoded C2 infrastructure (example indicators: domain npmjs.store, IP 216.74.123.126, and provided SHA256 hashes). The report explains evolving attacker tradecraft — fragmenting malicious workflows across benign-looking packages, long-horizon trust building, runtime-delivered encrypted payloads, sandbox evasion — and warns that generative AI expands attackers' capabilities (automated code generation, slopsquatting, prompt‑injection aimed at AI code reviewers); AWS/Inspector shared indicators to OSV (MAL-2026-3400) and integrated detections into GuardDuty/Inspector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
