importantSYS.SOURCE: The Hacker News• 2026-10-07T23:13:20+05:30
Malicious npm Packages Exploit Supply Chain to Deploy Overlord RAT and Data Stealers
Cybersecurity researchers uncovered eight malicious npm packages downloaded 40,767 times that deploy Overlord RAT and data stealers through supply chain attacks. The packages, linked to a Portuguese-speaking threat actor, use npm and Discord for distribution, with one package alone accounting for 37,419 downloads.
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts.
The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have
*** END OF TRANSMISSION ***