Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Executive Summary
Researchers uncovered a long-running npm supply‑chain attack, codenamed MALFEX, where 12 malicious packages were published since August 2023. Eight of these packages were downloaded 40,767 times and delivered the Overlord RAT and a credential stealer to infected hosts.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-07T17:43:20+00:00 - Category: threat-intel
Original Description: Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have
"If we learn to open our hearts, anyone, including the people who drive us crazy, can be our teacher."
— Pema Chodron