By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT

Cybersecurity researchers from CloudSEK and Checkmarx have detailed a persistent npm supply chain malware campaign, codenamed MALFEX, that has been distributing information stealers and remote access trojans (RATs) to compromised systems. The campaign is attributed to a single threat actor who has published at least 12 malicious packages on the npm registry since August 2023. Of these, eight packages have been identified as actively delivering malware, accumulating a significant number of downloads. Specifically, these eight malicious npm packages were downloaded a total of 40,767 times. The malware distributed includes the Overlord RAT, a sophisticated tool capable of remote control, and various information stealers designed to exfiltrate sensitive data from infected machines. The threat actor's modus operandi involves publishing seemingly legitimate packages that, upon installation, execute malicious code. This technique exploits the trust developers place in the npm ecosystem, a widely used package manager for JavaScript. The MALFEX campaign highlights the ongoing challenges in securing software supply chains, where vulnerabilities can be introduced through third-party code. The researchers noted that the threat actor has demonstrated a degree of sophistication in evading detection, suggesting a prolonged and deliberate effort to compromise systems. The Overlord RAT, a key component of this campaign, offers attackers extensive control over infected devices, enabling them to steal credentials, execute arbitrary commands, and potentially deploy further malicious payloads. The information stealers, on the other hand, are designed to target browser data, cryptocurrency wallets, and other sensitive personal information. The discovery of MALFEX underscores the critical need for enhanced security practices within the software development lifecycle, including rigorous vetting of third-party dependencies and the implementation of robust security scanning tools. The campaign's longevity, spanning from August 2023 to the present, indicates the difficulty in identifying and mitigating such threats once they are embedded within popular repositories. CloudSEK and Checkmarx have provided technical details of the campaign to aid in the detection and removal of the malicious packages and to inform the broader cybersecurity community about the evolving threat landscape. The specific number of downloads, 40,767, represents a substantial reach, indicating a considerable risk to developers and organizations relying on the npm ecosystem. The threat actor's continued activity and apparent success in distributing malware through this channel suggest that further malicious packages may emerge, necessitating ongoing vigilance and proactive security measures.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.