CyberSecurity News
Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
AI summary
Attackers have been running a malware campaign known as MALFEX, targeting the NPM ecosystem, since August 2023. As part of this campaign, they have published eight malicious packages. These packages have accumulated a total of 40,000 downloads. The campaign is a supply chain attack, indicating that the attackers are targeting the software supply chain. The MALFEX campaign has been ongoing for some time, with the malicious packages being downloaded by a significant number of users. The campaign's impact is likely to be substantial due to the large number of downloads.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to SecurityWeek.

