thehackernews.com 7 Oct 2026, 17:43 UTC

MALFEX npm Malware Campaign Seeds Windows PCs with Data Stealers and RATs

CYBERSECURITY researchers have disclosed a persistent npm supply-chain malware campaign, codenamed MALFEX, that has seeded Windows systems with information stealers and a remote access trojan (RAT). CloudSEK and Checkmarx identify the activity as the work of a lone operator who has published 12 packages since August 2023, eight of which are malicious.

The campaign uses three infection paths: loaders for Overlord, a Go‑written RAT that uses Solana transactions to extract its C2 address; a chain that installs movinlike, a Node[.]js stealer targeting Discord, browsers, Telegram and cryptocurrency wallets; and a downloader that delivers payloads. Overall, the eight packages have been downloaded 40,767 times, with 37,419 downloads attributed to function-flag, the primary driver since its July 2024 inception and its latest version released on 4 August 2025. Three packages—tlxbnhd, tldriver and mxdriver—act as Overlord loaders, triggering a Windows executable via lifecycle hooks.

Evidence cited by researchers notes distinct payload delivery: function-flag runs a postinstall hook to fetch a payload from remote servers; function-color depends on function-flag; and cdn-img-fetch in tandem with img-to-native retrieves and executes a Go executable that subsequently downloads a Node[.]js stealer. The operator’s identity is described as Portuguese-speaking, with repository metadata hinting at Brazilian origins, though CloudSEK cautions this language tie does not imply targeting Brazil.

The campaign is described as globally opportunistic, leveraging npm and Discord for distribution. Practical responses include heightened scrutiny of npm postinstall scripts and dependency trees, and monitoring for Overlord activity and the associated second-stage payloads.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline