CloudSEK and Checkmarx uncovered MALFEX, a long-running npm supply chain campaign that uses malicious packages to deliver the Overlord RAT, the movinlike stealer, and a downloader to Windows systems. The activity is linked to a lone Portuguese-speaking operator and includes packages such as function-flag, function-color, and cdn-img-fetch, with function-flag driving most of the downloads. #MALFEX #OverlordRAT #movinlike #function-flag #CloudSEK #Checkmarx
Keypoints
- The MALFEX campaign uses malicious npm packages to compromise Windows hosts.
- Three infection paths deliver the Overlord RAT, movinlike stealer, or a downloader.
- Packages tlxbnhd, tldriver, and mxdriver act as Overlord RAT loaders.
- function-flag and function-color are still live and continue to distribute payloads.
- The operator appears to be Portuguese-speaking and has published 12 packages since August 2023.
Read More: https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html