Incident2026-07-29

Amazon's threat intelligence team said one North Korea-linked group was behind compromises of four widely used JavaScript packages, including axios, debug and chalk, linking three of them to the group publicly for the first time. It also described how attackers use AI to mass-produce convincing but malicious code, register package names that AI coding assistants invent, and hide instructions meant to trick automated code reviewers. Amazon rates the attribution as medium confidence.

What changed

Only the axios compromise had been publicly tied to this group; the typo-crypto, debug and chalk incidents were unattributed.

What it unlocks

Security teams can use the published indicators of compromise and the OSV entry MAL-2026-3400 to check whether their build environments pulled the affected packages.

  • axios: 100M+ weekly downloads
  • 1 in 10 cloud environments hit in 2 hours
  • $12.5M joint open source defence fund

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.