MEDIUMSupply Chain
Global

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

·Source: SecurityWeek

Updated:

Executive Summary

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek .

Analysis

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek .
Source Attribution

Originally published by SecurityWeek on Oct 6, 2026.

Related Threats

MEDIUMSupply Chain

What Are the New Rules for Secure Open Source Consumption?

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/what-are-the-new-rules-for-secure-open-source-consumption" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Secure%20Open%20Source%20Consumption.png" alt="Image with concentric hexagons at the center containing a lock icon" class="hs-featured-image" style="width:auto !important; max-widt

Sonatype (Maven/npm)
MEDIUMSupply Chain

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

The Hacker News
MEDIUMSupply Chain

How Financial Services Companies Can Modernize Their Software Supply Chain

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

The Hacker News