Eight Malicious npm Packages Deliver Overlord RAT and Stealer in Supply Chain Campaign
Campaign codenamed MALFEX targets developers; 40,767 total downloads recorded

Key Takeaways
- Eight malicious npm packages delivered Overlord RAT and an information stealer in a campaign codenamed MALFEX.
- Packages have been downloaded 40,767 times total since August 2023.
- The threat actor is assessed to be operating alone.
- No CVEs are associated; the risk stems from malicious package authorship.
Related Security News

Canto Incognito Malware Targets Exposed AI and LLM Infrastructure, Infects 3,400+ Servers
Researchers have identified the Canto Incognito malware campaign targeting exposed artificial intelligence and large language model infrastructure globally. The financially motivated operation has infected over 3,400 servers, deploying cryptocurrency miners and expanding the botnet's reach. The attack vectors involve accessing poorly secured AI/LLM endpoints, though specific exploitation details remain limited in initial reporting.




