North Korean Hackers Compromise Major JavaScript Packages in Supply Chain Attack
Amazon security researchers revealed on July 29 that a North Korea-linked group successfully compromised four critical open-source JavaScript packages: axios, chalk, debug, and typo-crypto. The axios package alone serves over 100 million weekly downloads. The group used social engineering to gain maintainer access and insert malicious code. U.S. officials state the operation is part of Pyongyang's broader strategy to generate revenue and bypass sanctions to fund its nuclear program.
Date: July 29, 2026
Location: Global, United States
Conflict: Korean Peninsula Tensions
Category: cyber
Severity: HIGH
Source: Nextgov/FCW