- Amazon identified a threat actor linked to North Korea as responsible for multiple compromises of widely used open-source software libraries, including the axios package.
- The axios package was compromised in March 2026, and it is downloaded more than 100 million times each week.
- In March 2025, the DPRK-linked threat actor compromised the typo-crypto package.
- In September 2025, the same actor compromised the debug and chalk NPM packages.
- Social engineering was used by the threat actor to gain access to the packages by targeting a trusted maintainer and publishing a software update with malicious code.
Amazon Threat Intelligence has revealed that a North Korean threat actor is behind multiple compromises of popular open-source software libraries, including the axios package, which is downloaded over 100 million times weekly. This marks the first public link of these compromises to a single DPRK-linked group, according to CJ Moses, Amazon's chief information security officer.12
The threat actor has employed a consistent operational playbook, gaining access through social engineering tactics targeting trusted maintainers of the packages. Once access is secured, they publish software updates containing malicious code. In addition to axios, previous targets include the typo-crypto, debug, and chalk libraries, with compromises occurring in March 2025 and September 2025, respectively.5678

Moses emphasized that the same tactics were used across these compromises, indicating a systematic approach by the threat actor. Furthermore, Amazon researchers have raised concerns about the role of generative artificial intelligence (AI) in aiding adversaries to create novel code and content at scale, complicating the identification of malicious packages. Rush Carskadden, director of application security at Amazon, noted that the attack surface is expanding, necessitating AI-driven capabilities for security teams to counter these threats effectively.
As the landscape of open-source software continues to evolve, the implications of these attacks highlight the need for enhanced security measures to protect widely used libraries from malicious exploitation.
“Amazon's CJ Moses revealed that the DPRK-linked threat actor uses social engineering to compromise trusted maintainers, allowing malicious code to be published in updates. The threat actor's tactics have evolved, with generative AI aiding in the creation of novel malicious packages, complicating detection efforts for security teams.”