Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
Summary
Attackers have been running a malware campaign targeting the NPM JavaScript package registry since August 2023. Eight malicious packages have been published as part of the MALFEX campaign, which has amassed approximately 40,000 downloads.
IFF Assessment
FOE
This article describes a malicious supply chain campaign that has distributed malware, posing a threat to developers and their projects.
Defender Context
This campaign highlights the ongoing risks associated with supply chain attacks, particularly in popular package managers like NPM. Defenders should be vigilant about the packages they integrate into their projects, implementing robust dependency vetting and security scanning processes.