MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months
CloudSek links a set of malicious npm packages to one operator and two delivery arms, including active packages that remained available after a related package was seized. The campaign steals credentials and data from Windows systems.