None
NL
Amazon uncovers broad North Korean hacking campaign against open-source software
['David Dimolfetta', 'Cybersecurity Reporter', 'Nextgov Fcw']
Defense One - All Content
In each incident, the hackers tricked a trusted software maintainer and used the access to publish an update containing malicious code, according to Amazon.
Amazon said attackers are increasingly dividing a malicious operation among several packages that appear harmless when reviewed individually.
AI is also making malicious software harder to spot, the blog warned.
Concerns about open-source software security have increasingly drawn attention in Washington.
Last August, Nextgov/FCW first reported that an employee of the Russian technology company Yandex was the sole maintainer of a widely used open-source tool embedded in at least 30 pre-built software packages available to the Defense Department.