GoPlus has issued a warning about 26 malware packages released by North Korean hackers on the npm registry. These packages contain an installation script that automatically executes malicious code, downloading a Remote Access Trojan (RAT) capable of keylogging, clipboard theft, and credential collection. The attack, linked to the "Famous Chollima" hacking group, poses significant risks to privacy and assets. Users are urged to verify software sources before installation to avoid these threats.