Security

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

A malware campaign called MALFEX uses npm packages to deliver information stealers and remote access trojans to compromised systems. CloudSEK and Checkmarx researchers attribute the activity to a lone threat actor who has published 12 packages since August 2023; eight malicious packages have been downloaded 40,767 times.

Image: The Hacker News

Why it matters

The campaign exposes npm users to malware through widely downloaded packages, making dependency scrutiny important for developers and security teams.

Coverage 1 publisher

  1. The Hacker News

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Articles stay on their publishers’ sites; each link opens the original.