← Blog · · df00tech

MALFEX Campaign: Eight Malicious npm Packages Deliver Overlord RAT and Info-Stealer

security-news campaign

What Happened

According to The Hacker News, citing research from CloudSEK and Checkmarx, a long-running npm supply chain campaign tracked as MALFEX has been pushing information stealers and a remote access trojan (RAT) dubbed Overlord to developer machines. The researchers attribute the activity to a single threat actor who has published 12 malicious packages to npm since August 2023, eight of which were collectively downloaded 40,767 times before being identified.

Why It Matters for Defenders

npm supply chain attacks remain an effective way to reach developer and CI/CD environments directly, bypassing perimeter controls entirely since the malicious code is pulled in as a trusted dependency. A multi-year, low-and-slow publishing cadence from one actor suggests the packages were likely designed to blend in with legitimate tooling rather than trigger obvious red flags, and the download count indicates real-world reach into production and development pipelines. Organizations with developers who install npm packages outside of a vetted internal registry are potentially exposed, as are any CI/CD runners or build systems where these packages may have been pulled transitively.

What Defenders Should Watch For

  • Review recent npm install logs and lockfiles for unfamiliar or recently-published packages, especially ones with vague or generic names, low star counts, or a single-maintainer publishing history.
  • Hunt for unexpected outbound network connections or child-process execution originating from Node.js processes on developer workstations and build agents — a common postinstall/RAT behavior pattern.
  • Audit CI/CD pipeline dependency manifests for packages added without a corresponding code review or ticket.
  • Enforce dependency vetting (lockfile pinning, provenance checks, private registry proxying) and restrict outbound internet access from build environments where feasible.
  • Monitor endpoint telemetry for stealer-style behavior: credential file access, browser data harvesting, or RAT command-and-control check-ins following an npm install.

This item is still developing and the specific package names, indicators of compromise, and full technical breakdown had not yet been incorporated into this note at time of writing. For full details, see the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.