New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

Cybersecurity experts have found malicious code in a npm package after a malicious package that was a dependency of the Claude Opus large language model (LLM) project from Anthropic.

“validate-sdk/v2,” a utility software development kit (SDK) for hashing, validation, encoding/decoding, and safe random generation, is the package in question. It is listed on npm. Its true purpose, meanwhile, is to steal confidential information from the infiltrated environment. The package was initially added to the repository in October 2025 and appears to have been vibe-coded using generative artificial intelligence (AI).

ReversingLabs codenamed the malware campaign PromptMink and connected the activity to a larger campaign run by the North Korean threat actor Famous Chollima (also known as Shifty Corsair), which is responsible for the fraudulent IT Worker scam read more about New Wave of DPRK Attacks Uses AI-Inserted npm Malware Fake Firms and RATs

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *