Vendor
npm
- First Reported
- Sep 30, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (1)
- 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months
Malware (3)
Threat Actors (1)
MITRE ATT&CK (6)
Vendors (2)
Products (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.