North Korean Hackers Compromise Major JavaScript Packages in Supply Chain Attack

Amazon security researchers revealed on July 29 that a North Korea-linked group successfully compromised four critical open-source JavaScript packages: axios, chalk, debug, and typo-crypto. The axios package alone serves over 100 million weekly downloads. The group used social engineering to gain maintainer access and insert malicious code. U.S. officials state the operation is part of Pyongyang's broader strategy to generate revenue and bypass sanctions to fund its nuclear program.

Date: July 29, 2026

Location: Global, United States

Conflict: Korean Peninsula Tensions

Category: cyber

Severity: HIGH

Source: Nextgov/FCW

View this event on the live WAR 3.0 conflict map