Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Summary

Attackers have been running a malware campaign targeting the NPM JavaScript package registry since August 2023. Eight malicious packages have been published as part of the MALFEX campaign, which has amassed approximately 40,000 downloads.

IFF Assessment

FOE

This article describes a malicious supply chain campaign that has distributed malware, posing a threat to developers and their projects.

Defender Context

This campaign highlights the ongoing risks associated with supply chain attacks, particularly in popular package managers like NPM. Defenders should be vigilant about the packages they integrate into their projects, implementing robust dependency vetting and security scanning processes.

Read Full Story →