N. Korea Group Behind Multiple Open Source Supply Chain Attacks
Amazon researchers have identified the latest twist in supply-chain whack-a-mole: North Korea-linked groups are exploiting open-source ecosystems and AI coding agents at machine speed. The warning — that generative AI is erasing the historical signals defenders used to catch malicious packages — translates from corporate-speak into: the burglar has been handed the keys, the floor plan and a head start. Pyongyang's operators no longer need to persuade anyone to install anything; they simply squat inside the dependency tree and wait for the build to run.
Consider what is actually being said. The same generative models being marketed as tireless pair programmers are just as good at generating poisoned dependencies, and the tells that used to give the game away — odd formatting, suspicious obfuscation, a maintainer suddenly shipping minified blobs at 3am — are being washed out by the sheer volume of machine-written code. Amazon's researchers might as well have announced that someone replaced the smoke detector with a scented candle. The open-source ecosystem is a shared public good, which has always meant in practice that everyone benefits and no one is responsible, and now every downstream build also gets a complimentary taste of North Korea's handiwork.
None of this should surprise anyone who watched the industry hand its critical infrastructure to the same category of tool it claims to be defending against. The response, presumably, will be more AI, more agents, more 'security overlays' — each adding its own attack surface while pretending the problem is merely a staffing shortage. The honest summary of Amazon's research is that the defenders' radar has been jammed by the offence's own toolkit, and the North Koreans are enjoying a fine stretch of clear weather. Splendid timing for a dependency freeze.