[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:eight-malicious-npm-packages-downloaded-40-767-times-deliver-overlord-rat-and-st-muzdhj04":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"59aef2ec-14a6-4e6a-887c-71148e9eb91e","Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer","eight-malicious-npm-packages-downloaded-40-767-times-deliver-overlord-rat-and-st-muzdhj04","Eight malicious npm packages (40,767+ downloads) deliver Overlord RAT and movinlike stealer targeting Windows developers. The MALFEX campaign steals browser data, crypto wallets, and messaging credentials. If your development environment installed these packages, assume compromise.","critical","advisory",[],[13,14,15,16],"npm","Overlord RAT","movinlike","CloudSEK","Immediately audit npm install logs for 'function-flag' and seven related packages. Revoke credentials for any developer machine that installed them. Scan for C2 callbacks and browser\u002Fwallet access from affected systems.",[19],"a77889c8-c12f-4942-9fee-cd2ea52168a2",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Feight-malicious-npm-packages-downloaded.html","active","2026-10-10T10:07:24.931+00:00","2026-10-08T10:07:29.204188+00:00","2026-10-08T10:10:08.812404+00:00",[28],{"id":19,"title":6,"url":22}]