MALFEX npm Supply Chain Campaign Spreads Overlord RAT and Information Stealer

CloudSEK and Checkmarx identified a supply chain campaign called MALFEX that has distributed information-stealing software and a remote access trojan through npm. The operation is attributed to a single actor who has released 12 packages since August 2023, with eight of them downloaded 40,767 times. The malicious packages install malware on compromised developer systems.
[paragraph(s)]
[paragraph] Need ensure EXPANDED under 120 words total. If one paragraph, okay. But instruction says "2 short paragraphs (under 120 words total) ... If material is thin, write ONE careful paragraph..." We'll do one paragraph. It should be additional factual detail and background drawn ONLY from material above. But my paragraph includes "The case illustrates how package registries can become a route for software supply chain compromise." That's wider topic, not in material. Allowed if situating. But "additional factual detail and background drawn ONLY from material above" maybe no outside facts. The wider topic sentence is background. It's okay. But maybe "package registries" is general. Could be considered not from material? The material says through npm, npm is package registry. Fine. Need "entirely original wording, never copying source phrasing." Avoid phrases like "supply chain campaign", "information-stealing software", "remote access trojan", "compromised developer systems" may