Eight Malicious npm Packages Deliver Overlord RAT and Stealer, Notching 40,000 Downloads
A supply chain campaign that has quietly persisted on the npm registry for more than two years has been unmasked by researchers at CloudSEK and Checkmarx. The operation, tracked as MALFEX, revolves around a dozen packages published since August 2023. Eight of those packages remain live and have collectively been downloaded 40,767 times, according to the researchers. The payloads are designed to steal sensitive data and install a remote access trojan (RAT) known as Overlord RAT on compromised developer machines.
The campaign is attributed to a lone threat actor who has maintained a low profile while steadily publishing and updating malicious code. The scale of the downloads underscores how easily trust in open-source ecosystems can be abused: even a small number of packages, if they appear useful, can reach thousands of developers and CI/CD pipelines.
How the Packages Operate
The malicious packages masquerade as legitimate utilities, often using names and descriptions that blend into the npm ecosystem. Once installed, they execute a postinstall script that fetches a second-stage payload from attacker-controlled infrastructure. That payload is a JavaScript-based stealer that harvests credentials from browsers, cryptocurrency wallets, and other applications, and then drops Overlord RAT for persistent remote control.
The stealer component is particularly concerning because it targets developer environments, where credentials for source control, cloud providers, and package registries are frequently stored in plaintext or easily accessible configuration files. With those credentials, an attacker could pivot into private repositories, cloud accounts, and further supply chain attacks.
Overlord RAT, meanwhile, provides the attacker with a foothold for command-and-control (C2) communication, allowing them to execute arbitrary commands, exfiltrate files, and maintain persistence across reboots. The combination of stealthy initial access via npm and a full-featured RAT makes this campaign a significant risk for organizations that rely on JavaScript and Node.js.
A Long-Running but Low-Volume Operation
Unlike some high-profile supply chain attacks that flood a registry with hundreds of packages, MALFEX has been patient. The actor published packages in small batches, likely to avoid triggering automated detection systems that flag sudden spikes in new packages or downloads. The researchers note that the campaign has been active since August 2023, with some packages receiving updates as recently as this year.
This longevity suggests that the actor is not a smash-and-grab operation but rather someone focused on maintaining access and harvesting credentials over time. The use of npm as a distribution vector is also telling: developers often have elevated privileges and access to production systems, making them high-value targets.
Detection and Mitigation
CloudSEK and Checkmarx have published indicators of compromise (IOCs) and a list of the malicious packages. Organizations should immediately check their dependency trees for the named packages and remove them if found. Because the stealer targets browser and application data, any machine that installed one of these packages should be considered compromised and undergo a full credential rotation.
Beyond incident response, the campaign highlights the need for stronger supply chain security practices. Recommendations include:
- Use a software composition analysis (SCA) tool to scan dependencies for known malicious packages and vulnerabilities.
- Enforce lockfiles and pin dependencies to specific versions to prevent unexpected updates.
- Restrict postinstall scripts in CI/CD environments, or run them in sandboxed containers with limited network access.
- Monitor network egress from build servers for connections to unknown domains, which could indicate C2 traffic.
- Adopt a zero-trust approach for developer machines, limiting the blast radius of stolen credentials.
npm has been notified and is expected to remove the remaining malicious packages. However, the incident serves as a reminder that registry takedowns are reactive; the onus is on defenders to detect and respond quickly.
The Bigger Picture
MALFEX is part of a broader trend of attackers targeting open-source package managers. From PyPI to RubyGems, these ecosystems are attractive because they are built on implicit trust. A single malicious package can propagate through hundreds of projects, and the resulting access can be used for espionage, financial theft, or further supply chain compromise.
For security teams, the lesson is clear: treat third-party code as untrusted, verify dependencies, and assume that credentials on developer endpoints are at risk. The 40,767 downloads of these eight packages represent tens of thousands of potential entry points—and a reminder that supply chain security is not just about the code you write, but the code you import.
Source: The Hacker News