Supply ChainOct 5, 2026
MALFEX npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work
MALFEX npm campaign delivers RATs, info-stealers, or open Node.js processes as payloads.
Summary
The MALFEX campaign is an ongoing supply-chain attack targeting the npm JavaScript package registry. Attackers are injecting malicious code into legitimate packages, which then deliver various payloads including Remote Access Trojans (RATs), information stealers, or open Node.js processes. The campaign is notable for the adversary signing their malicious code, potentially to evade detection or mislead analysis.
Indicators of Compromise
- malware — MALFEX
Entities
npm (technology)