Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Eight malicious npm packages, downloaded 40,767 times, installed Overlord RAT and a Node.js stealer.
CloudSEK and Checkmarx disclosed MALFEX, an npm supply-chain campaign linked to a lone operator who published 12 packages since August 2023, eight of them malicious. Collectively downloaded 40,767 times, the packages use install hooks to load the Go-based Overlord RAT, which reads its command-and-control address from Solana transactions, or movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets. function-flag accounts for 37,419 downloads, and function-flag, function-color, and cdn-img-fetch were still live. Overlord has also appeared in WordPress exploitation of CVE-2026-63030 and CVE-2026-60137 and in a fake Zoom macOS installer that overlaps the UNK_DeadDrop cluster.