Hackread.com posted a great example of cyber security in action. A long-running supply-chain campaign has used malicious npm packages to deliver a remote access trojan (RAT), steal credentials and maintain access to compromised Windows systems. CloudSEK’s Global Threat Intelligence team called the operation MALFEX and linked it to a single operator active since August 2023.[1]
Hacking& Cracking - The operator used multiple npm accounts containing the Malfex name, along with a GitHub account ca