Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.

Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.

New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.