Threat investigators connect four previous npm library breaches affecting axios, debug, chalk, and typo-crypto packages, to a single source. After investigating a series of seemingly unrelated high-profile open-source software attacks on open-source software packages, Amazon’s threat-intelligence unit has established that four previous attacks can be linked to a single North Korean hacking group. The firm has announced that the breaches of four …
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.