The malware, likely developed using a large language model, according to CrowdStrike's Counter Adversary Operations, was distributed through typosquatted and slopsquatted npm packages.