Amazon’s threat intelligence team has traced a North Korean open-source software attack back to a smaller, earlier compromise that served as a probe before the main assault on the axios package. The group used a little-known npm package to test their access before deploying a larger, more impactful compromise — a pattern that’s becoming increasingly common among state-sponsored threat groups.

The timeline shows the group establishing footholds through smaller targets first, then using those as pivot points to reach higher-value infrastructure. This approach mirrors tactics seen in the Mastra AI framework compromise from June, suggesting the same group or a closely affiliated one is running a coordinated supply chain campaign across multiple projects.

Why This Matters: Supply chain attacks are getting more sophisticated — and more patient. The fact that North Korean actors are using small npm packages as reconnaissance tools before hitting major dependencies means organizations relying on popular libraries may already be compromised through obscure transitive dependencies. Security teams need to audit their full dependency trees, not just direct dependencies, and monitor for anomalous package behavior.

Source: CyberScoop

By Allan