In each incident, the hackers tricked a trusted software maintainer and used the access to publish an update containing malicious code, according to Amazon. Amazon said attackers are increasingly dividing a malicious operation among several packages that appear harmless when reviewed individually. AI is also making malicious software harder to spot, the blog warned. Concerns about open-source software security have increasingly drawn attention in Washington. Last August, Nextgov/FCW first reported that an employee of the Russian technology company Yandex was the sole maintainer of a widely used open-source tool embedded in at least 30 pre-built software packages available to the Defense Department.