Skip to main content
Emerging ThreatsSupply Chain Attacks

Malicious npm Packages Deliver Overlord RAT and Stealer in Supply Chain Attack

Software development workspace with laptop, coding books, and blurred npm registry webpage on screen.
37,419 — the number of times a single malicious npm package, "function-flag," was downloaded in a supply-chain operation that researchers say delivered Remote Access Trojans and information stealers to Windows hosts.

MALFEX campaign: scope and discovery

Cybersecurity firms CloudSEK and Checkmarx have cataloged a long-running npm supply-chain campaign they code-named MALFEX. The firms say a lone operator published 12 packages to the npm registry since August 2023; eight of those packages have been flagged as malicious. Collectively the eight malicious packages were downloaded 40,767 times, with "function-flag" accounting for 37,419 of those downloads. Checkmarx and CloudSEK are the sources for the findings presented here.

Three distinct infection pathways and their payloads

According to the reporting, the MALFEX delivery architecture targets Windows systems via three separate paths:

  • A loader chain that deploys Overlord, an open-source remote access trojan written in Go whose C2 address is extracted via Solana transactions;
  • A chain that installs "movinlike," a Node.js stealer designed to harvest data from Discord, web browsers, Telegram, and cryptocurrency wallets;
  • A generic downloader route used to fetch and execute follow-on payloads.

Which packages do what

CloudSEK and Checkmarx identified the eight malicious packages by name: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch. The firms describe a functional split among them.

  • tlxbnhd, tldriver, and mxdriver act as Overlord RAT loaders. Their malicious code is triggered via npm lifecycle hooks that download and run a Windows executable.
  • img-to-native and native-runner form part of a chain that depends on cdn-img-fetch to retrieve and execute a Go executable; that Go payload then fetches a Node.js stealer capable of harvesting sensitive data.
  • function-flag contains a postinstall hook that runs a JavaScript payload to download an external payload; each version of the package was observed serving its payload from a different remote location. function-color contains no embedded payload but lists function-flag as a dependency, enabling indirect execution.

Concrete behavior observed in function-flag

Checkmarx highlighted the behavior in function-flag version 1.7.3. In that release the postinstall script runs example.js, which invokes the package's ASCII-art function with the "Bloody" font. Checkmarx reported that the font value triggers a hidden routine that downloads an executable named node.exe from cdnzona.discloud.app, a host on a Brazilian application hosting service; the file is saved to %APPDATA%\\node.exe and launched with its window hidden.

CloudSEK provided contextual attribution clues about the operator, noting Portuguese-language metadata: "The operator is Portuguese-speaking, the git commits sit at -0300, one repository description is in Portuguese, and the GitHub display name and email give a common Brazilian handle." CloudSEK explicitly cautioned that this linguistic footprint is not an argument about geographic targeting, but rather a trace of the operator's own linguistic space.

Overlord reuse and cross-campaign overlaps

CloudSEK and Checkmarx reported that Overlord RAT has appeared outside the MALFEX npm deliveries. Since July 2026, Overlord was observed in two other campaigns: one exploiting WordPress vulnerabilities CVE-2026-63030 and CVE-2026-60137 (also called wp2shell), and another that used a fake Zoom installer on macOS. The macOS fake-Zoom campaign shares tactical overlaps with a suspected North Korea-aligned threat cluster referenced as UNK_DeadDrop, according to the researchers.

What this means for security teams, npm maintainers, and developers

  • Security teams and incident responders should note the multiplicity of delivery vectors: npm package lifecycle hooks, chained fetchers, and executable dropper behavior (for example, saving node.exe to %APPDATA% and running it hidden). Those behaviors can enable rapid follow-on compromise when packages are installed in development or CI environments.
  • npm registry operators and open-source maintainers should watch for packages that declare innocuous functions but list malicious dependencies (function-color declaring function-flag) and for packages that change remote payload endpoints between versions, as MALFEX versions reportedly did.
  • Application developers and DevOps teams should be aware that a single high-volume package can drive most of a campaign's installs — "function-flag" was responsible for 37,419 of 40,767 total downloads — and that attackers may use wide-reaching distribution channels such as npm and Discord to reach global targets opportunistically.

The MALFEX disclosures show a compact, repeatable approach: publish packages that appear harmless, trigger code via lifecycle hooks or dependencies, and fetch established stealers or RATs. The operators change payload endpoints across versions and reuse tooling — including Overlord — across unrelated campaigns. That combination makes blocking a single indicator of compromise an incomplete defense; defenders will need to consider both registry hygiene and runtime detection to catch these chains.

Original reporting: https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html