Security
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
The Hacker News·October 7, 2026·1 min read
Cybersecurity researchers disclosed a long-running npm supply chain malware campaign, codenamed MALFEX by CloudSEK and Checkmarx, that pushes information stealers and remote access trojans to compromised hosts. The activity is assessed to be the work of a lone threat actor who published 12 packages since August 2023, eight of which were downloaded 40,767 times.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
