New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Source: The Hacker News · Category: Nation-State
DPRK threat actors injected malware into npm package '@validate-sdk/v2' used by Anthropic's Claude; campaign uses AI, fake firms, and RATs. If the firm uses Claude AI or any npm dependencies with '@validate-sdk/v2' in supply chain, conduct immediate audit; client data processed through Claude may be exposed.