Four distinct compromises of open source Node Package Manager (NPM) libraries can now be confidently linked to one threat actor backed by the North Korean government, according to Amazon’s threat ...