(31 Jul 2026) A North Korean cyber espionage group was behind attacks on four widely used open-source software libraries relied upon by developers around the world, according to a newly disclosed security report from Amazon, highlighting the growing risks to the global software supply chain.
The findings, first reported by Voice of America citing Amazon’s Threat Intelligence team, attribute the compromises of the popular libraries Axios, Debug, Chalk and Crypto to a single North Korean-linked hacking group. While the group’s involvement in the Axios attack had previously been known, Amazon said this is the first time the other three incidents have been publicly linked to the same actor.
The report comes as North Korea’s cyber operations continue to generate growing concern across the technology and cryptocurrency sectors. According to blockchain security firm Blockaid’s Onchain Security Report for the first half of 2026, hackers stole approximately $1.1 billion in cryptocurrency worldwide during the six-month period, with TraderTraitor — a subgroup of North Korea’s Lazarus Group — accounting for $690 million, or about 55% of the total, according to Voice of America.
Read more here.



