
highMalware
Eight Malicious npm Packages Deliver Overlord RAT and Stealer in Supply Chain Campaign
Researchers from CloudSEK and Checkmarx have identified a supply chain malware campaign operating under the codename MALFEX. Eight malicious npm packages, published since August 2023, have been downloaded 40,767 times. The packages deliver Overlord RAT and an information stealer to compromised hosts. The activity is attributed to a lone threat actor. No CVEs are associated with the campaign, as the threat involves malicious packages distributed via the npm registry.
The Hacker News1 min read