Lazarus Group concealed a four-module remote access toolkit inside six fake npm Rollup polyfill packages that fired at import ...
Telling an LLM that 2 + 2 = 5 is enough to make it follow forbidden instructions.