Cybersecurity experts have revealed an extensive and ongoing malware campaign involving npm packages, targeting users with information stealers and remote access trojans (RAT). This operation, identified by CloudSEK and Checkmarx as ‘MALFEX,’ is believed to be orchestrated by a single threat actor who has released 12 npm packages, with eight being identified as harmful.
Npm Packages as Malware Vectors
The attack primarily focuses on Windows systems, utilizing three distinct pathways. Firstly, it deploys Overlord, an open-source RAT developed in Go, which leverages Solana transactions for command-and-control (C2) activities. Secondly, it installs ‘movinlike,’ a Node.js-based stealer aimed at extracting data from Discord, web browsers, Telegram, and cryptocurrency wallets. Lastly, it incorporates a downloader to facilitate these malicious activities.
A list of the malicious packages includes ‘tlxbnhd,’ ‘tldriver,’ ‘mxdriver,’ ‘img-to-native,’ ‘native-runner,’ ‘function-flag,’ ‘function-color,’ and ‘cdn-img-fetch.’ These packages have been downloaded 40,767 times, with ‘function-flag’ alone accounting for 37,419 downloads since its initial release in July 2024. The latest update occurred on August 4, 2025.
In-depth Analysis of Package Functions
The project description for the ‘function-flag’ npm package includes a message in Portuguese, indicating a personal touch by the so-called Malfex team. Three packages, ‘tlxbnhd,’ ‘tldriver,’ and ‘mxdriver,’ serve as loaders for Overlord RAT, triggering harmful code through lifecycle hooks to execute a Windows executable.
Another group of packages, such as ‘img-to-native,’ works in conjunction with ‘cdn-img-fetch’ to install a Go executable, which then retrieves a Node.js stealer designed to collect sensitive information. Notably, ‘function-flag’ contains a post-installation hook that runs a JavaScript script to download additional payloads from varying remote locations. ‘Function-color’ does not host its own payload but depends on ‘function-flag.’
Broader Implications and Attribution
Overlord RAT has also been linked to other campaigns since July 2026, including those exploiting WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) and a macOS campaign deploying a fake Zoom installer, potentially tied to a North Korean-aligned threat group known as UNK_DeadDrop.
CloudSEK highlights that the operator appears to be Portuguese-speaking, with several indicators pointing to a Brazilian origin. However, this linguistic link does not imply the campaign targets Brazil specifically, as npm and Discord offer global platforms, and the targeting remains opportunistic.
This revelation underscores the critical need for heightened vigilance and protective measures against supply chain attacks, as the global reach and impact of such campaigns continue to grow.
