North Korean Hackers Target NPM Libraries in Supply Chain Attack
Amazon Threat Intelligence uncovered a DPRK-linked threat actor compromising popular Node Package Manager libraries used globally. Cloud engineers should audit their npm dependencies immediately and implement strict supply chain verification to block malicious package installations.
source: [aws/security-blog]