
Amazon Confirms Supply Chain Attack Campaign Detected Earlier by Italy
hacker_attacksmalwarecybersecurity_newscybersecurityprivacyACNAIgenerative_AIAmazonapplicationscyber_attackscyber_attackauthenticationtwo_factor_authenticationcloudClusitNIS_2_Directivehuman_factorsuppliersguidehackersartificial_intelligenceopen_sourcesocial_engineeringsupply_chaintrojanEU
Amazon confirmed a supply chain attack campaign targeting software packages, which Italy had already detected. The attackers, linked to North Korea, used social engineering techniques to gain the trust of package administrators and obtain elevated privileges. The campaign specifically targeted NPM packages, exploiting the dependency ecosystem. Two separate incidents were analyzed by Amazon, highlighting the structural threat to supply chain security. No specific dates, technical indicators, or CVE IDs were mentioned in the report.