As many as nine packages have been identified as uploaded to npm between August 9 and 12, 2023. This includes: ws-paso-jssdk, pingan-vue-floating, srm-front-util, cloud-room-video, progress-player, ynf-core-loader, ynf-core-renderer, ynf-dx-scripts, and ynf-dx-webpack-plugins.
"Due to the sophisticated nature of the attack and the small number of affected packages, we suspect this is another highly targeted attack"
North Korean Hackers Suspected
https://blog.phylum.io/sophisticated-highly-targeted-attacks-continue-to-plague-npm/