Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Summary

Cybersecurity researchers have uncovered a persistent npm supply chain malware campaign that distributes information stealers and remote access trojans (RATs). This campaign, dubbed MALFEX, involves a single threat actor who has released at least 12 malicious packages since August 2023, with eight of them being downloaded over 40,000 times.

IFF Assessment

FOE

This campaign represents a significant threat to developers and organizations relying on npm packages, as it actively distributes malware designed to steal information and provide remote access.

Defender Context

This incident highlights the ongoing risks associated with software supply chain attacks, particularly within the npm ecosystem. Defenders should be vigilant about the packages they incorporate into their projects, implement robust dependency scanning, and consider implementing stricter code review processes to identify potentially malicious code before it's integrated.

Read Full Story →