Amazon's threat research team has linked a single threat actor to four separate open source software compromises, including a March 2026 incident targeting the axios NPN library. The attribution points to a North Korean-backed group, raising concerns about coordinated supply chain attacks against widely-used development tools.
Why it matters: Open source supply chain attacks pose a critical risk to enterprise software security, and attribution of coordinated campaigns helps organizations understand threat patterns and prioritize defensive measures.