Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News - Oct 7, 2026

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

Read full article

More News

About Us
Logo

In-Depth Science delivers comprehensive and compelling news and analysis on everything science and technology, seven days a week in a reader-friendly format.

Contact us: sales[at]indepthscience.com

Copyright © 2015 - 2026 In-Depth Science. All Rights Reserved.