[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCYi2GO8wqa5hKFCeRsbUL1HmGgWndspWEOp4S8WuHmk":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"a77889c8-c12f-4942-9fee-cd2ea52168a2","Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer","eight-malicious-npm-packages-downloaded-40-767-times-deliver-overlord-rat-and-st-39f490","Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have","A long-running npm supply chain campaign, codenamed MALFEX, has been discovered distributing information stealers and remote access trojans (RATs). The campaign, attributed to a lone Portuguese-speaking threat actor, involved eight malicious npm packages downloaded over 40,000 times, with 'function-flag' being the most popular. These packages target Windows systems by delivering the Overlord RAT and the movinlike stealer, which harvests data from browsers, wallets, and messaging apps.","Eight malicious npm packages downloaded over 40k times deliver Overlord RAT and stealer.","Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer Ravie LakshmananOct 07, 2026Supply Chain \u002F Malware Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious. The attack is designed to infect Windows systems through three separate pathways - A loader for Overlord, an open-source RAT written in Go that uses Solana transactions to extract the command-and-control (C2) address A chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets, and A downloader The list of identified malicious packages is below - tlxbnhd tldriver mxdriver img-to-native native-runner function-flag (Still live) function-color (Still live) cdn-img-fetch (Still live) In all, these packages have been collectively downloaded 40,767 times. Of these, 37,419 downloads correspond to \"function-flag,\" making it the largest driver of this activity. The package was first published in July 2024. The latest version was released on August 4, 2025. The project description for the npm package features a welcome message written in Portuguese that states: \"This project was created with a lot of love and dedication by the Malfex team, whose owner is Murizada.\" Three of the packages, \"tlxbnhd,\" \"tldriver,\" and \"mxdriver,\" act as Overlord RAT loaders, with the malicious code triggered via lifecycle hooks to download and run a Windows executable. A second subset of the npm packages, such as \"img-to-native,\" requires \"cdn-img-fetch\" to retrieve and execute a Go executable, which then fetches a Node.js stealer capable of harvesting sensitive data. Present within \"function-flag\" is a postinstall hook that runs a JavaScript payload to download a payload from a remote server. Each version of the package has been found to serve a payload from a different location. The \"function-color\" package embeds no payload of its own, but lists \"function-flag\" as a dependency. \"In 1.7.3, the current latest version, the postinstall script runs example.js, which calls the package's ASCII art function with the Bloody font,\" Checkmarx said. \"That font value triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, a host on a Brazilian application hosting service, saves it to %APPDATA%\\node.exe, and runs it with its window hidden.\" Interestingly, Overload RAT has been observed in two other campaigns since July 2026: one involving the exploitation of WordPress flaws (CVE-2026-63030 and CVE-2026-60137, aka wp2shell) and a macOS campaign in which a fake Zoom installer is used to deploy the RAT. The fake Zoom installer campaign shares tactical overlaps with a suspected North Korea-aligned threat cluster dubbed UNK_DeadDrop. \"The operator is Portuguese-speaking, the git commits sit at -0300, one repository description is in Portuguese, and the GitHub display name and email give a common Brazilian handle,\" CloudSEK said. \"None of this is an argument that the campaign targets Brazil. It is a piece of attribution to the operator's own linguistic space and nothing more. The delivery is npm and Discord, both of which are global; the second-stage targeting is opportunistic.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Malware, Supply Chain, Windows Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Feight-malicious-npm-packages-downloaded.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgopANe3MXyNNOXog__x1pF53wYoQxinI47tN9gLrZSzJfumz-Dg05ZfyjiGsqF47Pugj71iZ1buX7OEiupWYa09xVQdu7DKOMX5NO-uGKCF0UjNila0x5fNiYw5NWEX1TUQTPidjT5NnGmPwM_6mGfKcOxqcjZuPAZLdzRX5u_TXJM76GQ6mQOkikw_kxo\u002Fs1600\u002Fnpm-malware.jpg","2026-10-07T17:43:20+00:00","2026-10-07T18:00:14.350745+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"MALFEX","campaign",{"name":22,"type":23},"UNK_DeadDrop","threat_actor",{"name":25,"type":26},"npm","product",{"name":28,"type":26},"Overlord RAT",{"name":30,"type":26},"movinlike",{"name":32,"type":33},"CloudSEK","vendor","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":34,"icon":36,"name":37,"slug":38},null,"Supply Chain","supply-chain",[40,42,47,52],{"category":41},{"id":34,"icon":36,"name":37,"slug":38},{"category":43},{"id":44,"icon":36,"name":45,"slug":46},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":53},{"id":54,"icon":36,"name":55,"slug":56},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[58,60,62,66],{"type":46,"value":28,"context":59},"Remote access trojan delivered by malicious npm packages.",{"type":46,"value":30,"context":61},"Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets.",{"type":63,"value":64,"context":65},"cve","CVE-2026-63030","WordPress vulnerability exploited in a separate campaign involving Overlord RAT.",{"type":63,"value":67,"context":65},"CVE-2026-60137"]