The company said the activity has been ongoing since early 2025 and reflects North Korea's continued focus on software supply chain attacks. Social Engineering Enabled Package CompromisesAccording to AWS, attackers gained access by socially engineering maintainers of legitimate open-source packages before publishing malicious versions of the software. Cybersecurity firm Wiz previously reported that approximately 1 in 10 cloud environments were affected during the debug and chalk supply chain incident within a two-hour period. He added that "one successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions." As software supply chain attacks continue to evolve, AWS said organizations should strengthen package verification practices, monitor software dependencies and remain alert to increasingly sophisticated social engineering techniques targeting open-source maintainers.