Security researchers have detailed a persistent malware campaign targeting the npm package registry. Dubbed MALFEX, the operation has been active since August 2023, during which time attackers have published eight malicious packages. The campaign has managed to accumulate approximately 40,000 downloads before being identified.

The findings highlight the ongoing risk posed by supply chain attacks to open-source ecosystems. By publishing packages that appear legitimate, attackers can trick developers into installing compromised code, potentially spreading the infection to downstream applications. The longevity of the MALFEX campaign and the download count suggest a degree of success in evading initial detection.

While the specific packages have not been named in the summary, the report underscores the importance of package validation and monitoring for unusual activity in registries. Developers are advised to audit dependencies and be wary of newly published packages with suspicious characteristics.