NEWS

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The MALFEX campaign hid a Solana-C2 RAT and a credential stealer in npm postinstall hooks; three of the eight packages are still live.

Dylan H.

News Desk

October 7, 2026
4 min read
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

A Long-Running npm Campaign Surfaces

Researchers at CloudSEK and Checkmarx have disclosed a long-running npm supply chain malware campaign, codenamed MALFEX, that pushed information stealers and a remote access trojan to developers through eight packages collectively downloaded 40,767 times.


The Packages

PackageRole
function-flagMost downloaded (37,419 of the 40,767 total); first published July 2024
tlxbnhd, tldriver, mxdriverSupporting/downloader packages
img-to-native, native-runnerSupporting/downloader packages
function-color, cdn-img-fetchSupporting/downloader packages

function-flag alone accounts for the overwhelming majority of the campaign's reach, with its latest version published as recently as August 4, 2025. The operator behind the campaign has published 12 packages to npm since August 2023, under names that tend to blend into legitimate-sounding utility libraries.


What Gets Installed

The campaign delivers through npm's postinstall lifecycle hook — code that runs automatically the moment a package is installed, before a developer ever imports or reviews it. Once triggered, it can pull down a Windows executable or run a hidden routine that fetches additional payloads from remote infrastructure. Three distinct components have been identified:

  1. Overlord RAT – an open-source, Go-based remote access trojan that uses Solana blockchain transactions as its command-and-control channel, making takedown and traffic-blocking harder than with a conventional C2 server
  2. Movinlike Stealer – a Node.js-based credential and data stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets
  3. A downloader module – responsible for retrieving and executing further payloads after initial compromise

Attribution and Targeting

CloudSEK and Checkmarx assess the operator is likely Portuguese-speaking, based on repository descriptions and GitHub metadata, with some references pointing to a Brazilian handle ("Murizada"). Targeting appears opportunistic rather than tailored — the campaign relies on broad npm installs and Discord-based distribution rather than targeting specific organizations, with Windows systems as the payload's primary target.

The campaign has been active since August 2023, with package publishing activity continuing through at least August 2025. As of the researchers' report, three of the eight identified packages remain live on the npm registry.


Why This Matters

Postinstall hooks are one of the most consistently abused mechanisms in npm supply chain attacks precisely because they execute without any explicit action from the developer beyond running npm install — no import statement, no function call, nothing that would show up in a code review of the application that depends on the package. A Solana-based C2 channel adds a further wrinkle: blockchain transactions are harder to blocklist than IP addresses or domains, and the traffic can blend in with legitimate crypto-related network activity.

The 40,767 download count, spread across a multi-year campaign with a rotating set of package names, is also a reminder that these campaigns don't need a single viral package to do damage — a steady trickle of installs across a dozen low-profile utility libraries adds up, and some of that exposure is still live today.

  1. Audit installed dependencies for the named packages (function-flag, tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-color, cdn-img-fetch) and remove any that are present
  2. Treat postinstall scripts as a review priority — consider npm install --ignore-scripts for unfamiliar or low-reputation packages, then review scripts manually before allowing them to run
  3. Monitor outbound traffic to Solana RPC endpoints from developer and CI machines where it wouldn't normally be expected, as a potential indicator of Overlord RAT C2 activity
  4. Rotate credentials (Discord tokens, browser-saved logins, crypto wallet keys) on any machine where one of the flagged packages was installed

Sources