Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.

MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages. Linked to an apparent single operator active since August 2023, the campaign delivers Overlord RAT, the movinlike information stealer, and a separate downloader concealed inside an ASCII-art utility. The largest contributor, function-flag, accounted for 37,419 downloads and has contained malicious code since […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: