Cybersecurity Alert: North Korean Hackers Target Developers with Malicious npm Packages
A new malware campaign named “PromptMink” has been uncovered, involving malicious code hidden in popular npm packages. This attack, linked to the North Korean group Famous Chollima, exploits software packages like “@validate-sdk/v2,” masquerading as legitimate tools for developers.
The malware, first detected in October 2025, can access sensitive data, including cryptocurrency wallet information. Developers using affected packages, particularly in the Web3 space, are at risk. The campaign employs a sophisticated multi-layered approach, initially presenting benign packages that later download malicious code.
To protect against this threat, developers should regularly audit their dependencies, avoid unverified packages, and keep security software updated.
Risk Level: High
With the increasing evolution of these attacks, vigilance is essential to safeguard sensitive information in the software development community.
Source: View Original Report
