Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Outside spending nears $2 billion – and the biggest groups pull further ahead • OpenSecrets

    October 8, 2026

    The US has backed Libya’s Haftar clan. The UK should not make the same mistake | Libya

    October 8, 2026

    Amazon is sending Prime class action settlement payments. Are you eligible?

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Outside spending nears $2 billion – and the biggest groups pull further ahead • OpenSecrets
    • The US has backed Libya’s Haftar clan. The UK should not make the same mistake | Libya
    • Amazon is sending Prime class action settlement payments. Are you eligible?
    • Democrats sue US President Trump over taxpayer-funded ad campaign | Donald Trump News
    • The 23 Best Prime Day Deals Under $100 That You Can Still Get (2026)
    • What Happens When a Trusted Model Repo Changes? Unsloth Studio Re-Checks Before It Runs
    • SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
    • US government moves $470 million in seized crypto to Coinbase wallets, raising Bitcoin sale questions
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 07, 2026Supply Chain / Malware

    Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts.

    The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious.

    • The attack is designed to infect Windows systems through three separate pathways –
    • A loader for Overlord, an open-source RAT written in Go that uses Solana transactions to extract the command-and-control (C2) address
    • A chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets, and
    • A downloader
    Cybersecurity

    The list of identified malicious packages is below –

    • tlxbnhd
    • tldriver
    • mxdriver
    • img-to-native
    • native-runner
    • function-flag (Still live)
    • function-color (Still live)
    • cdn-img-fetch (Still live)

    In all, these packages have been collectively downloaded 40,767 times. Of these, 37,419 downloads correspond to “function-flag,” making it the largest driver of this activity. The package was first published in July 2024. The latest version was released on August 4, 2025.

    The project description for the npm package features a welcome message written in Portuguese that states: “This project was created with a lot of love and dedication by the Malfex team, whose owner is Murizada.”

    Three of the packages, “tlxbnhd,” “tldriver,” and “mxdriver,” act as Overlord RAT loaders, with the malicious code triggered via lifecycle hooks to download and run a Windows executable.

    A second subset of the npm packages, such as “img-to-native,” requires “cdn-img-fetch” to retrieve and execute a Go executable, which then fetches a Node.js stealer capable of harvesting sensitive data.

    Present within “function-flag” is a postinstall hook that runs a JavaScript payload to download a payload from a remote server. Each version of the package has been found to serve a payload from a different location. The “function-color” package embeds no payload of its own, but lists “function-flag” as a dependency.

    Cybersecurity

    “In 1.7.3, the current latest version, the postinstall script runs example.js, which calls the package’s ASCII art function with the Bloody font,” Checkmarx said. “That font value triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, a host on a Brazilian application hosting service, saves it to %APPDATA%node.exe, and runs it with its window hidden.”

    Interestingly, Overload RAT has been observed in two other campaigns since July 2026: one involving the exploitation of WordPress flaws (CVE-2026-63030 and CVE-2026-60137, aka wp2shell) and a macOS campaign in which a fake Zoom installer is used to deploy the RAT. The fake Zoom installer campaign shares tactical overlaps with a suspected North Korea-aligned threat cluster dubbed UNK_DeadDrop.

    “The operator is Portuguese-speaking, the git commits sit at -0300, one repository description is in Portuguese, and the GitHub display name and email give a common Brazilian handle,” CloudSEK said. “None of this is an argument that the campaign targets Brazil. It is a piece of attribution to the operator’s own linguistic space and nothing more. The delivery is npm and Discord, both of which are global; the second-stage targeting is opportunistic.”

    deliver Downloaded Malicious npm Overlord Packages RAT Stealer Times
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    Ransomware recovery CEO charged over secret ransom payments

    Citizen Lab Slams Trump, ‘Techno-Fascist’ Executives

    FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

    OpenAI Agent Escape Causes Wikimedia Service Outage

    Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Outside spending nears $2 billion – and the biggest groups pull further ahead • OpenSecrets

    October 8, 2026

    The US has backed Libya’s Haftar clan. The UK should not make the same mistake | Libya

    October 8, 2026

    Amazon is sending Prime class action settlement payments. Are you eligible?

    October 8, 2026

    Democrats sue US President Trump over taxpayer-funded ad campaign | Donald Trump News

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Outside spending nears $2 billion – and the biggest groups pull further ahead • OpenSecrets

    October 8, 2026

    The US has backed Libya’s Haftar clan. The UK should not make the same mistake | Libya

    October 8, 2026

    Amazon is sending Prime class action settlement payments. Are you eligible?

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.