Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Uncovered in Extensive Malware Campaign

Malicious npm Packages Uncovered in Extensive Malware Campaign

Posted on October 7, 2026 By CWS

Cybersecurity experts have revealed an extensive and ongoing malware campaign involving npm packages, targeting users with information stealers and remote access trojans (RAT). This operation, identified by CloudSEK and Checkmarx as ‘MALFEX,’ is believed to be orchestrated by a single threat actor who has released 12 npm packages, with eight being identified as harmful.

Npm Packages as Malware Vectors

The attack primarily focuses on Windows systems, utilizing three distinct pathways. Firstly, it deploys Overlord, an open-source RAT developed in Go, which leverages Solana transactions for command-and-control (C2) activities. Secondly, it installs ‘movinlike,’ a Node.js-based stealer aimed at extracting data from Discord, web browsers, Telegram, and cryptocurrency wallets. Lastly, it incorporates a downloader to facilitate these malicious activities.

A list of the malicious packages includes ‘tlxbnhd,’ ‘tldriver,’ ‘mxdriver,’ ‘img-to-native,’ ‘native-runner,’ ‘function-flag,’ ‘function-color,’ and ‘cdn-img-fetch.’ These packages have been downloaded 40,767 times, with ‘function-flag’ alone accounting for 37,419 downloads since its initial release in July 2024. The latest update occurred on August 4, 2025.

In-depth Analysis of Package Functions

The project description for the ‘function-flag’ npm package includes a message in Portuguese, indicating a personal touch by the so-called Malfex team. Three packages, ‘tlxbnhd,’ ‘tldriver,’ and ‘mxdriver,’ serve as loaders for Overlord RAT, triggering harmful code through lifecycle hooks to execute a Windows executable.

Another group of packages, such as ‘img-to-native,’ works in conjunction with ‘cdn-img-fetch’ to install a Go executable, which then retrieves a Node.js stealer designed to collect sensitive information. Notably, ‘function-flag’ contains a post-installation hook that runs a JavaScript script to download additional payloads from varying remote locations. ‘Function-color’ does not host its own payload but depends on ‘function-flag.’

Broader Implications and Attribution

Overlord RAT has also been linked to other campaigns since July 2026, including those exploiting WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) and a macOS campaign deploying a fake Zoom installer, potentially tied to a North Korean-aligned threat group known as UNK_DeadDrop.

CloudSEK highlights that the operator appears to be Portuguese-speaking, with several indicators pointing to a Brazilian origin. However, this linguistic link does not imply the campaign targets Brazil specifically, as npm and Discord offer global platforms, and the targeting remains opportunistic.

This revelation underscores the critical need for heightened vigilance and protective measures against supply chain attacks, as the global reach and impact of such campaigns continue to grow.

The Hacker News Tags:Checkmarx, CloudSEK, cyber threat, Cybersecurity, Discord, information stealer, malicious software, Malware, Node.js, NPM, OVERLORD RAT, remote access trojan, supply chain, supply chain attack

Post navigation

Previous Post: Hackers Breach Domain Registries for Unauthorized Certificates
Next Post: CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator

Related Posts

Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group The Hacker News
What is Identity Dark Matter? What is Identity Dark Matter? The Hacker News
Chrome Extensions Linked to Adware and Fake Traffic Chrome Extensions Linked to Adware and Fake Traffic The Hacker News
Unitree G1 EDU Robots Face Critical Security Vulnerabilities Unitree G1 EDU Robots Face Critical Security Vulnerabilities The Hacker News
Compromised npm Packages Distribute RAT via Node.js Compromised npm Packages Distribute RAT via Node.js The Hacker News
Kaltura Vulnerabilities Permit Remote File Access and Code Execution Kaltura Vulnerabilities Permit Remote File Access and Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Discord Users’ Data Exposed in Double Counter Breach
  • Attackers Exploit ccTLDs to Acquire Google Certificates
  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
  • Malicious npm Packages Uncovered in Extensive Malware Campaign
  • Hackers Breach Domain Registries for Unauthorized Certificates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Discord Users’ Data Exposed in Double Counter Breach
  • Attackers Exploit ccTLDs to Acquire Google Certificates
  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
  • Malicious npm Packages Uncovered in Extensive Malware Campaign
  • Hackers Breach Domain Registries for Unauthorized Certificates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark