Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.
The MALFEX npm campaign ships Overlord RAT and movinlike to steal browser passwords, Discord tokens, and crypto wallets.
Checkmarx describes MALFEX, an npm supply-chain campaign active since August 2023 that shipped Windows malware in eight packages totaling 40,767 downloads by October 1, 2026. Install scripts and package-load hooks deliver Overlord RAT, which uses a scheduled task named Maiden, and a Go downloader for the movinlike Node.js stealer. movinlike targets Discord clients, browser cookies and passwords, Telegram Desktop sessions, and wallets including MetaMask, Phantom, and Coinbase Wallet, then exfiltrates data through a Discord webhook. Three packages remained installable, and OSV advisories did not cover every malicious version.