Back to advisories

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Eight malicious npm packages (40,767+ downloads) deliver Overlord RAT and movinlike stealer targeting Windows developers. The MALFEX campaign steals browser data, crypto wallets, and messaging credentials. If your development environment installed these packages, assume compromise.

CRITICALAdvisoryOct 08, 2026
Action required
Immediately audit npm install logs for 'function-flag' and seven related packages. Revoke credentials for any developer machine that installed them. Scan for C2 callbacks and browser/wallet access from affected systems.
Affected products
npmOverlord RATmovinlikeCloudSEK