Back to Feed
Supply ChainOct 5, 2026

MALFEX npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work

MALFEX npm campaign delivers RATs, info-stealers, or open Node.js processes as payloads.

Summary

The MALFEX campaign is an ongoing supply-chain attack targeting the npm JavaScript package registry. Attackers are injecting malicious code into legitimate packages, which then deliver various payloads including Remote Access Trojans (RATs), information stealers, or open Node.js processes. The campaign is notable for the adversary signing their malicious code, potentially to evade detection or mislead analysis.

Indicators of Compromise

  • malware — MALFEX

Entities

npm (technology)