Eight malicious npm packages have been downloaded over 40,000 times in a prolonged attack campaign that delivers Overlord RAT and a custom data stealer. Researchers have named the operation MALFEX, attributing it to a single actor who has published twelve packages since August 2023—eight of them now flagged as malicious.
What Does MALFEX Do?
This threat targets Windows systems using three distinct delivery chains. One vector involves npm packages—such as “tlxbnhd,” “tldriver,” and “mxdriver”—that run lifecycle hooks to load a Windows executable, which serves as a loader for Overlord RAT. A separate batch uses packages like “img-to-native” in conjunction with “cdn-img-fetch”: these pull down a Go executable that then installs a Node.js stealer designed to extract data from browsers, Telegram, Discord, and cryptocurrency wallets. Meanwhile, the “function-flag” package carries a postinstall hook that reaches out to a remote server, downloads node.exe, saves it under %APPDATA%, and executes it stealthily. There’s also “function-color,” which depends on “function-flag,” and “cdn-img-fetch,” which helps orchestrate payload delivery.
Scale, Attribution, and Persistence
So far, the packages have racked up 40,767 downloads—with “function-flag” alone accounting for 37,419. First published in July 2024, its latest version was released on August 4, 2025. The campaign’s naming (“MALFEX”), the use of Portuguese in descriptions, and git metadata suggest a Brazilian or Portuguese-speaking operator—though there’s no evidence the actor is targeting any specific region; the threat is global. Delivery channels involve npm’s open ecosystem and Discord, while subsequent infections depend on opportunities presented by the victim’s environment.
Overlord RAT’s Reputation and Broader Context
Overlord RAT is an open-source tool written in Go that can use Solana blockchain transactions to fetch its command-and-control server address. Its use in Malfex joins other recent campaigns leveraging WordPress vulnerabilities—specifically CVE-2026-63030 and CVE-2026-60137—and a macOS scheme involving a fake Zoom installer, both spotted since mid-2026. Those campaigns display overlap in techniques with a cluster known as UNK_DeadDrop, linked to North Korea in prior analyses.
The actor behind MALFEX appears motivated to fund or stage long-term access and exfiltration rather than purely opportunistic damage. The use of stealer modules, loaders, chain-of-dependency attacks, and stealth in execution shows advanced tactics likely intended to maintain persistence and broaden reach.
Why It Matters: This operation highlights persistent risks in the npm ecosystem. Attackers can piggyback malicious code into popular development workflows, hide payloads in dependencies, and evade detection with multi-stage loading. For development teams, supply-chain defenders, and security operations, key takeaways include locking down dependency sources, auditing postinstall scripts, monitoring unexpected network or file activity, and ensuring DevSecOps processes catch hidden-loader behavior.