New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Cybersecurity experts have found malicious code in a npm package after a malicious package that was a dependency of the Claude Opus large language model (LLM) project from Anthropic.
"validate-sdk/v2," a utility software development kit (SDK) for hashing, validation, encoding/decoding, and safe random generation, is the package in question. It is listed on npm. Its true purpose, meanwhile, is to steal confidential information from the infiltrated environment. The package was initially added to the repository in October 2025 and appears to have been vibe-coded using generative artificial intelligence (AI).
ReversingLabs codenamed the malware campaign PromptMink and connected the activity to a larger campaign run by the North Korean threat actor Famous Chollima (also known as Shifty C...

