Amazon links North Korea to open-source software attacks targeting popular libraries; axios package compromised in March 2026, downloaded over 100 million times weekly
Swarnabha ChattarajRush CarskaddenCJ MosesAmazon.com, Inc.University of ChicagoArgonne National Laboratory

Amazon links North Korea to open-source software attacks targeting popular libraries; axios package compromised in March 2026, downloaded over 100 million times weekly

Amazon has linked a North Korean threat actor to a series of compromises of popular open-source software libraries, including the axios package, which is downloaded over 100 million times weekly. The group has employed social engineering tactics to introduce malicious code into these widely used libraries.

anl.gov+1 source30 July 2026 · 20:51 UTC
CuriousCats Full Story

Amazon Threat Intelligence has revealed that a North Korean threat actor is behind multiple compromises of popular open-source software libraries, including the axios package, which is downloaded over 100 million times weekly. This marks the first public link of these compromises to a single DPRK-linked group, according to CJ Moses, Amazon's chief information security officer.12

The threat actor has employed a consistent operational playbook, gaining access through social engineering tactics targeting trusted maintainers of the packages. Once access is secured, they publish software updates containing malicious code. In addition to axios, previous targets include the typo-crypto, debug, and chalk libraries, with compromises occurring in March 2025 and September 2025, respectively.5678

Moses emphasized that the same tactics were used across these compromises, indicating a systematic approach by the threat actor. Furthermore, Amazon researchers have raised concerns about the role of generative artificial intelligence (AI) in aiding adversaries to create novel code and content at scale, complicating the identification of malicious packages. Rush Carskadden, director of application security at Amazon, noted that the attack surface is expanding, necessitating AI-driven capabilities for security teams to counter these threats effectively.

As the landscape of open-source software continues to evolve, the implications of these attacks highlight the need for enhanced security measures to protect widely used libraries from malicious exploitation.

Key Insight
“Amazon's CJ Moses revealed that the DPRK-linked threat actor uses social engineering to compromise trusted maintainers, allowing malicious code to be published in updates. The threat actor's tactics have evolved, with generative AI aiding in the creation of novel malicious packages, complicating detection efforts for security teams.”
CuriousCats studied:
1
anl.gov
“Researchers at Argonne and the University of Chicago have developed a new open-source software that predicts how energy is transferred between tiny defects in solid materials.”
anl.gov →
2
meritalk.commeritalk.com
“Amazon identified a threat actor linked to the Democratic People’s Republic of Korea (DPRK) as the group behind multiple recent compromises of widely used open-source software libraries.”
meritalk.com →
Ask CuriousCats
Who is CJ Moses from Amazon?
What tactics are used by the DPRK-linked actor?
Why is this attack significant for open-source software?
Are other countries facing similar cybersecurity threats?
How do these tactics compare to traditional cyber attacks?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
One story brought you here.
CuriousCats brings you everything else worth knowing.
Get CuriousCats