VMTech
Discuss a project →

MALFEX npm campaign spreads Overlord RAT and data stealer

MALFEX npm campaign spreads Overlord RAT and data stealer

Eight npm packages linked to MALFEX malware activity

CloudSEK and Checkmarx have detailed a long-running npm supply-chain campaign, codenamed MALFEX, in which eight malicious packages were downloaded a combined 40,767 times. The activity is assessed as the work of a lone threat actor that appears to have published 12 packages since August 2023; eight have been identified as malicious.

The campaign targets Windows systems through three delivery paths: loaders for the Go-based Overlord remote-access trojan, a chain that installs the movinlike Node.js information stealer, and a downloader. The named packages are tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color and cdn-img-fetch.

Downloads were heavily concentrated in function-flag, which accounted for 37,419 of the total. It was first published in July 2024, and its latest version was released on August 4, 2025. Its project description includes a Portuguese welcome message referring to the Malfex team and an owner called Murizada.

Lifecycle hooks turn installation into execution

Three packages—tlxbnhd, tldriver and mxdriver—act as Overlord RAT loaders. Their malicious logic is triggered through npm lifecycle hooks that download and run a Windows executable. Overlord is an open-source RAT written in Go that uses Solana transactions to obtain its command-and-control address.

A separate chain involving packages such as img-to-native requires cdn-img-fetch. It retrieves and executes a Go executable, which then fetches the movinlike Node.js stealer. That stealer is designed to collect data from Discord, browsers, Telegram and cryptocurrency wallets.

Function-flag contains a postinstall hook that launches JavaScript to download a remote payload, and each examined version used a different payload location. Function-color does not embed a payload itself, but declares function-flag as a dependency, extending the exposure through a transitive package relationship.

Checkmarx said version 1.7.3 of function-flag runs example.js after installation. The script calls an ASCII-art function with the Bloody font, which triggers hidden logic to download node.exe from cdnzona.discloud.app, save it as %APPDATA%\node.exe, and run it with a hidden window.

Packages remain available and targeting is opportunistic

Function-flag, function-color and cdn-img-fetch were still live when the researchers published their findings. CloudSEK said indicators including Portuguese-language material, Git commits at -0300 and a Brazilian-style online handle point to the operator’s linguistic environment, not to a Brazil-specific victim focus. Delivery through npm and Discord is global, while second-stage targeting is described as opportunistic.

Overlord has also appeared in two campaigns since July 2026: attacks exploiting WordPress flaws CVE-2026-63030 and CVE-2026-60137, also called wp2shell, and a macOS campaign using a fake Zoom installer. The latter showed tactical overlaps with the suspected North Korea-aligned cluster UNK_DeadDrop.

For businesses, the immediate implication is to examine direct and transitive npm dependencies, especially packages that execute lifecycle or postinstall scripts. Build and endpoint controls should treat package installation as executable code activity, because a dependency can retrieve a second-stage payload before an application is ever deployed.

#cybersecurity#npmsecurity#supplychain#malware
Open analytics
On the site 0 views
min read 4 07.10.2026
Instagram

MALFEX npm campaign spreads Overlord RAT and data stealer

Open the post on Instagram ↗