Hackread.com posted a great example of cyber security in action. A long-running supply-chain campaign has used malicious npm packages to deliver a remote access trojan (RAT), steal credentials and maintain access to compromised Windows systems. CloudSEK’s Global Threat Intelligence team called the operation MALFEX and linked it to a single operator active since August 2023.[1]
Hacking& Cracking - The operator used multiple npm accounts containing the Malfex name, along with a GitHub account called cavecrew. CloudSEK found references to “Murizada” in one package’s README, where the name was listed as the owner of the Malfex team. The researchers linked at least 12 npm packages and a GitHub repository to the operation.
CloudSEK also discovered indications that the operator is Portuguese-speaking, including Portuguese text in a repository and a Brazilian-linked GitHub handle, although the researchers did not link the campaign to Brazil.
One Chain Delivers Overlord RAT - CloudSEK’s research identified packages including tlxbnhd, tldriver and mxdriver using npm installation scripts to download a Windows executable disguised as a PNG file. The file contained an encrypted script that ultimately loaded Overlord RAT, an open-source Go-based RAT.
MALFEX infection chain shows how malicious npm packages ultimately deliver Overlord RAT. (Credit: CloudSEK)
Overlord can capture screens, record keystrokes, provide remote shell access and interact with a victim’s desktop. This version of the malware can use the Solana blockchain to retrieve updated command-and-control (C2) server addresses, allowing the malware to locate its control infrastructure.
Antivirus& Malware - Another Chain Steals Discord and Browser Data: A second delivery chain used img-to-native and its dependency cdn-img-fetch to retrieve a PNG file from GitHub. The package decrypted an embedded payload and eventually fetched a 64 MB Node.js bundle.
The bundle injected code into Discord clients and stole Discord authentication tokens and account information. It also targeted browser cookies and credentials, cryptocurrency wallets and Telegram session data. The stolen information was sent to an attacker-controlled Discord webhook.
Malicious Packages Remained Available - Some of the malicious packages remained available long after the campaign began. Five MALFEX packages had received security advisories, while three malicious packages remained without advisories.
One of them, function-flag, remained malicious and installable for 14 months. Another, cdn-img-fetch, remained available after npm removed its parent package, img-to-native. The related function-color package also pulled function-flag as a dependency.
Malicious npm packages and related infrastructure linked to the MALFEX campaign. (Credit: CloudSEK)
The MALFEX findings come amid continued abuse of npm for supply-chain attacks. In August 2026, Hackread reported that the Shai-Hulud campaign compromised Keyv and related packages, with the malware spreading to additional npm packages and stealing developer credentials.
Hacking & Cracking - CloudSEK warned that removing one malicious npm package is not always enough when related packages, dependencies and external payloads remain active. The researchers recommend checking connected components instead of relying only on individual npm security advisories.
This article is shared at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC). For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com
Weekly Cyber Intelligence Briefings:
- Reporting: https://www.redskyalliance.org/
- Website: https://www.redskyalliance.com/
- LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929
[1] https://hackread.com/malfex-npm-windows-rat-steals-discord-browser-data/#google_vignette
Comments