ConciseSignal
Following

Malicious npm packages deliver Overlord RAT and stealer

Researchers have uncovered a prolonged npm supply chain malware campaign dubbed MALFEX, delivering the Overlord remote access trojan and a data stealer targeting Windows systems. Eight identified packages, collectively downloaded over 40,000 times, infected machines mainly through postinstall scripts and dependency chains. The most downloaded package, "function-flag," was first published in July 2024. Three packages remain live as of the latest report.

Why it mattersSupply chain attacks through package managers like npm threaten developers and end users by enabling the spread of malware at scale. The discovery highlights industry-wide risks due to easy access to malicious components within trusted software ecosystems.

Sources covering this

SecurityWeekHeadline onlyLong-Running NPM Malware Campaign Accumulates 40,000 Downloads10:34 AM →The Hacker NewsEight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer5:43 PM →
Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity