Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News by The Hacker News
October 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananOct 07, 2026Supply Chain / Malware

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts.

The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious.

  • The attack is designed to infect Windows systems through three separate pathways –
  • A loader for Overlord, an open-source RAT written in Go that uses Solana transactions to extract the command-and-control (C2) address
  • A chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets, and
  • A downloader

The list of identified malicious packages is below –

  • tlxbnhd
  • tldriver
  • mxdriver
  • img-to-native
  • native-runner
  • function-flag (Still live)
  • function-color (Still live)
  • cdn-img-fetch (Still live)

In all, these packages have been collectively downloaded 40,767 times. Of these, 37,419 downloads correspond to “function-flag,” making it the largest driver of this activity. The package was first published in July 2024. The latest version was released on August 4, 2025.

The project description for the npm package features a welcome message written in Portuguese that states: “This project was created with a lot of love and dedication by the Malfex team, whose owner is Murizada.”

Three of the packages, “tlxbnhd,” “tldriver,” and “mxdriver,” act as Overlord RAT loaders, with the malicious code triggered via lifecycle hooks to download and run a Windows executable.

A second subset of the npm packages, such as “img-to-native,” requires “cdn-img-fetch” to retrieve and execute a Go executable, which then fetches a Node.js stealer capable of harvesting sensitive data.

Present within “function-flag” is a postinstall hook that runs a JavaScript payload to download a payload from a remote server. Each version of the package has been found to serve a payload from a different location. The “function-color” package embeds no payload of its own, but lists “function-flag” as a dependency.

“In 1.7.3, the current latest version, the postinstall script runs example.js, which calls the package’s ASCII art function with the Bloody font,” Checkmarx said. “That font value triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, a host on a Brazilian application hosting service, saves it to %APPDATA%node.exe, and runs it with its window hidden.”

Interestingly, Overload RAT has been observed in two other campaigns since July 2026: one involving the exploitation of WordPress flaws (CVE-2026-63030 and CVE-2026-60137, aka wp2shell) and a macOS campaign in which a fake Zoom installer is used to deploy the RAT. The fake Zoom installer campaign shares tactical overlaps with a suspected North Korea-aligned threat cluster dubbed UNK_DeadDrop.

“The operator is Portuguese-speaking, the git commits sit at -0300, one repository description is in Portuguese, and the GitHub display name and email give a common Brazilian handle,” CloudSEK said. “None of this is an argument that the campaign targets Brazil. It is a piece of attribution to the operator’s own linguistic space and nothing more. The delivery is npm and Discord, both of which are global; the second-stage targeting is opportunistic.”



Source link

The Hacker News

The Hacker News

Next Post

BioBrain Study Finds Consumers Embrace AI but Still Want Human Oversight

Recommended.

Macronix Flash Memory Family Includes Highest Level of Automotive Safety

Macronix Flash Memory Family Includes Highest Level of Automotive Safety

January 6, 2026
Stocks making the biggest moves premarket: BlackRock, PayPal, ASML, Morgan Stanley & more

Stocks making the biggest moves premarket: BlackRock, PayPal, ASML, Morgan Stanley & more

July 15, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio