Cybersecurity3 min reading time
'Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks
TechRadar
Read full postAmazon Threat Intelligence has linked a North Korean hacking group to multiple recent compromises of popular NPM software libraries, including axios, debug, chalk, and typo-crypto. The group used social engineering to manipulate trusted maintainers and distribute malicious updates, exploiting generative AI to create convincing malware and evade detection. These attacks have impacted millions of developers and cloud environments by infiltrating widely used open source packages.



