Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
thehackernews.com Oct 8, 2026

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

AI-summarised brief · reviewed before publication

Cybersecurity researchers exposed a long‑running npm supply‑chain attack dubbed MALFEX, orchestrated by a lone threat actor. Twelve malicious packages, including “function‑flag,” “tlxbnhd,” and “img‑to‑native,” were published since August 2023, collectively downloaded 40,767 times. The packages use post‑install hooks to download and execute Windows executables or Go binaries that deliver an Overlord RAT or a Node.js stealer. The operator’s Portuguese‑language commits and Brazilian handle suggest a Brazilian origin, but the attack targets are global.

💡 Why It Matters

  • · The campaign demonstrates how seemingly benign npm packages can become sophisticated delivery mechanisms for remote‑access trojans and data stealers, expanding the threat surface for developers and enterprises alike.