
PromptMink: ReversingLabs discloses 7-month DPRK supply chain campaign using LLM Optimization to target AI coding agents via npm
CybersecuritySupply Chain AttackNorth KoreaAI SecuritynpmLLMDPRKmalwareAPT
ReversingLabs identified a North Korean (DPRK) cyber campaign spanning seven months that leveraged LLM Optimization (LLMO) techniques. The campaign targeted AI coding agents by distributing malicious packages through the npm ecosystem. The operation, dubbed "PromptMink," involved the use of compromised or typosquatted npm packages to execute the attack.