< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

npm supply-chain attacks identified in MALFEX and PhantomSub campaigns

Cybersecurity researchers have identified multiple malicious npm supply-chain campaigns targeting developers through compromised packages.

CloudSEK uncovered MALFEX, a long-running campaign where a malicious postinstall script remained undetected for 14 months. The operation utilized packages like ‘function-flag’ to deploy the Overlord Remote Access Trojan (RAT), which is capable of keylogging, screen capture, and remote shell access. The attackers employed a Solana blockchain-based command-and-control mechanism to rotate infrastructure via encrypted on-chain messages. Other chains targeted cryptocurrency wallets, browser credentials, and Discord or Telegram data.

Separately, researchers from OX Security identified a cluster of 101 npm packages involved in a campaign called ‘PhantomSub’. These packages abuse the ‘Baileys’ WhatsApp open-source project to stealthily add developers' WhatsApp accounts to unauthorized groups and newsletter channels without consent. The malicious packages have been downloaded approximately 490,000 times, with significant recent activity recorded in the last 30 days.

Entities

CloudSEK · GitHub · OX Security · WhatsApp · npm