Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
A malware campaign called MALFEX uses npm packages to deliver information stealers and remote access trojans to compromised systems. CloudSEK and Checkmarx researchers attribute the activity to a lone threat actor who has published 12 packages since August 2023; eight malicious packages have been downloaded 40,767 times.