MALFEX npm Packages Deliver Overlord RAT and movinlike
Eight malicious MALFEX npm packages, downloaded 40,767 times since August 2023, install Windows Overlord RAT or the movinlike stealer.
Checkmarx, with CloudSEK also cited by The Hacker News, disclosed MALFEX, an npm supply-chain campaign a lone operator has run since August 2023 by publishing 12 packages, eight of them malicious and aimed at Windows developers. The Hacker News, GBHackers, and Cyber Security News put collective downloads at 40,767 by October 1, 2026, while SecurityWeek said more than 40,000; function-flag alone is 37,419 in the more specific counts (SecurityWeek said it exceeds 37,000), and GBHackers said that package has contained malicious code since July 2025. Install hooks and version-specific downloaders deliver Overlord RAT—which can capture screens, log keys, open a remote shell, and search files, is described by The Hacker News as Go-based and as reading its command-and-control address from Solana transactions, and persists with a scheduled task named Maiden that Cyber Security News says runs every five minutes—or the Node.js stealer movinlike. Cyber Security News added that one path fetches a file labeled as a PNG that is actually a Microsoft IExpress archive and launches Overlord through a signed AutoIt interpreter, while another appends AES-encrypted data to a real PNG and uses a Go downloader to retrieve movinlike, which targets Discord, browser cookies and passwords, Telegram Desktop sessions, and wallets including MetaMask, Phantom, and Coinbase Wallet before exfiltrating via a Discord webhook. SecurityWeek said exposure is limited to direct installs and that no popular packages depend on the malware; function-flag, function-color, and cdn-img-fetch were still installable around October 1, and OSV coverage differs—SecurityWeek said advisories cover six packages but incompletely for cdn-img-fetch, while GBHackers said function-flag and function-color had none. The Hacker News also reported Overlord in WordPress exploitation of CVE-2026-63030 and CVE-2026-60137 and in a fake Zoom macOS installer overlapping the UNK_DeadDrop cluster.
- Checkmarx, with CloudSEK also cited by The Hacker News, disclosed MALFEX, an npm campaign a lone operator has run since August 2023 by publishing 12 packages, eight of them malicious and aimed at Windows.
- The Hacker News, GBHackers, and Cyber Security News put downloads at 40,767 by October 1, 2026; SecurityWeek said more than 40,000. function-flag alone is 37,419 (SecurityWeek: exceeds 37,000) and GBHackers said it has been malicious since…
- Install hooks and version-specific downloaders deliver Overlord RAT—screen capture, keylogging, remote shell, and file search—or the Node.js stealer movinlike. The Hacker News said Overlord is Go-based and reads its C2 address from Solana…
Coverage timelineoldest first · each row is one article
- · 2d agoLong-Running NPM Malware Campaign Accumulates 40,000 Downloads
SecurityWeek· 63
Checkmarx says a long-running npm campaign passed 40,000 downloads of packages dropping Overlord RAT and stealers.
- · 1d agoEight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
The Hacker News· 73
Eight malicious npm packages, downloaded 40,767 times, installed Overlord RAT and a Node.js stealer.
- · 18h ago
Vulnerabilities in this storyAll →
- CVE-2026-630309.811%WordPress Core Route Confusion (wp2shell) Enables SQL Injection to RCEpublished · WordPress Core KEV PoC ×4+1 related
| CVE | Vulnerability | CVSS |
|---|