Last updated: October 8, 2026 at 8:36 AM UTC
All 909 Vulnerability 368 Breach 144 Threat 390 Defense 7
Tag: malfex (1 article)Clear

Eight malicious npm packages downloaded over 40,000 times deliver Overlord RAT and credential stealer

CloudSEK and Checkmarx detailed MALFEX, a campaign they attribute to a lone actor who has published eight malicious npm packages downloaded 40,767 times in total, with function-flag alone accounting for 37,419. The Windows-focused packages deliver three payloads: Overlord, an open-source Go remote access trojan that pulls its command-and-control address from Solana transactions; a Node.js stealer that targets Discord, browsers, Telegram, and cryptocurrency wallets; and a downloader. Lifecycle and postinstall hooks fetch and run remote executables, with one package saving a hidden node.exe to the AppData directory. Three packages, function-flag, function-color, and cdn-img-fetch, were still live on npm at publication.

Check
Audit npm dependencies for the named MALFEX packages, remove any that are present, and check Windows hosts for Overlord RAT activity and a hidden node.exe in the AppData directory.
Affected
Windows developers who installed the MALFEX packages, especially function-flag, may be infected with the Overlord remote access trojan or a stealer targeting browsers, Telegram, and wallets.
Fix
Remove the malicious packages, rebuild affected Windows systems, rotate credentials for browsers, Discord, Telegram, and wallets, and block the known payload download domains.