Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
CloudSEK and Checkmarx uncovered MALFEX, a long-running npm supply chain campaign that uses malicious packages to deliver the Overlord RAT, the movinlike stealer, and a downloader to Windows systems. The activity is linked to a lone Portuguese-speaking operator and includes packages such as function-flag, function-color, and cdn-img-fetch, with function-flag driving most of the downloads. #MALFEX #OverlordRAT #movinlike #function-flag #CloudSEK #Checkmarx

Keypoints

  • The MALFEX campaign uses malicious npm packages to compromise Windows hosts.
  • Three infection paths deliver the Overlord RAT, movinlike stealer, or a downloader.
  • Packages tlxbnhd, tldriver, and mxdriver act as Overlord RAT loaders.
  • function-flag and function-color are still live and continue to distribute payloads.
  • The operator appears to be Portuguese-speaking and has published 12 packages since August 2023.

Read More: https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html