Malicious npm packages deliver Overlord RAT and stealers via hidden hooks
Eight malicious npm packages in the MALFEX campaign have been downloaded over 40,000 times, delivering remote access trojans and information stealers to Windows systems.
Cybersecurity researchers from CloudSEK and Checkmarx have exposed a persistent supply chain attack targeting the npm registry. Codenamed MALFEX, this campaign involves a lone threat actor who has published multiple malicious packages since August 2023. The operation aims to infect Windows hosts with remote access trojans and data stealers through deceptive open-source libraries.
What happened
The investigation identified eight malicious packages among twelve published by the actor. These packages have been collectively downloaded 40,767 times. The most significant contributor to this volume is a package named "function-flag," which accounts for 37,419 of those downloads. First published in July 2024, its latest version was released on August 4, 2025. The project description for this package includes a message in Portuguese claiming it was created with love by the "Malfex team."
The malicious code operates through three distinct infection pathways. The first involves loader packages that deploy Overlord, an open-source remote access trojan written in Go. The second pathway installs a Node.js stealer called movinlike, which targets sensitive data from Discord, web browsers, Telegram, and cryptocurrency wallets. The third pathway acts as a simple downloader to retrieve additional payloads from remote servers.
Researchers noted that the operator appears to be Portuguese-speaking, with git commits timestamped at -0300 and GitHub details pointing to a Brazilian handle. However, analysts emphasize that this linguistic footprint does not mean Brazil is the primary target. The delivery mechanism via npm and Discord is global, and the subsequent targeting of victims appears opportunistic rather than geographically specific.
How it works
The attack relies heavily on npm lifecycle hooks, specifically postinstall scripts, to execute malicious code automatically when a developer installs the package. For instance, the "function-flag" package contains a postinstall hook that runs a JavaScript payload. This script downloads further payloads from varying remote locations depending on the package version. Another package, "function-color," does not contain malware itself but lists "function-flag" as a dependency, thereby triggering the malicious installation process indirectly.
In the case of the Overlord RAT loaders, such as "tlxbnhd," "tldriver," and "mxdriver," the malicious code is triggered via lifecycle hooks to download and execute a Windows executable. Overlord uses Solana blockchain transactions to extract its command-and-control address, making detection more difficult. Another subset of packages, including "img-to-native," requires "cdn-img-fetch" to retrieve a Go executable. This executable then fetches the Node.js stealer capable of harvesting credentials and wallet data.
Checkmarx highlighted a specific technique in version 1.7.3 of "function-flag." The postinstall script runs a file called example.js, which calls an ASCII art function using a font value named "Bloody." This specific font value triggers a hidden routine that downloads node.exe from a Brazilian hosting service, saves it to the user's AppData folder, and runs it with the window hidden to avoid detection.
Key details
- Eight malicious npm packages have been identified, with three still live on the registry: "function-flag," "function-color," and "cdn-img-fetch."
- The campaign has generated 40,767 total downloads, with "function-flag" responsible for the vast majority at 37,419 downloads.
- The malware delivers Overlord RAT, which uses Solana transactions for command-and-control communication, and the movinlike stealer.
- Infection vectors include npm lifecycle hooks, dependency chains, and hidden routines triggered by specific function arguments like font names.
- The threat actor shows linguistic ties to Brazil but targets victims globally through opportunistic infection of Windows systems.
- Overlord RAT has also been observed in separate campaigns exploiting WordPress flaws and distributing fake Zoom installers for macOS.
Why it matters
This campaign highlights the continued risk of supply chain attacks in open-source ecosystems. Developers often trust npm packages implicitly, assuming that community-vetted libraries are safe. However, the use of lifecycle hooks allows attackers to execute code during installation, bypassing static analysis tools that only scan the source code repository. The high download count of "function-flag" suggests that many developers may have inadvertently compromised their development environments or production systems.
For engineering teams, the implications extend beyond immediate malware removal. The use of legitimate-looking project descriptions and the modular nature of the attack, where one package depends on another to trigger malware, make detection challenging. Security tools must now look deeper into dependency trees and runtime behaviors during installation, not just at the code stored in version control. The overlap with other threat clusters, such as UNK_DeadDrop, also suggests that these tactics are being shared or adopted across different groups, increasing the overall threat landscape.
What you can do
- Audit your project dependencies immediately to ensure none of the identified malicious packages are present in your lock files.
- Configure your package manager to restrict or alert on the execution of postinstall and preinstall scripts during package installation.
- Implement software composition analysis tools that can detect known malicious packages and suspicious behavioral patterns in dependencies.
- Monitor network traffic from development machines for unusual outbound connections to unknown hosts or blockchain networks like Solana.
- Educate development teams about the risks of adding new dependencies without thorough review, especially from lesser-known authors.
- Keep operating systems and security software updated to detect and block known indicators of compromise associated with Overlord RAT and movinlike.



