AI Weekly Malaysia

Back to items Summaries

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

ID
32900
Status
summarized
Published
08 Oct 2026, 1:43 AM
Fetched
08 Oct 2026, 2:58 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
08 Oct 2026, 2:59 AM
Tags
Audience
developersvibe_coders

What happened

CloudSEK and Checkmarx disclosed MALFEX, an npm supply-chain campaign attributed to a lone actor who has published 12 packages since August 2023, eight of them flagged malicious: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch. The packages have 40,767 total downloads, 37,419 of which come from function-flag alone (first published July 2024, latest version August 4, 2025), and they deliver three payload paths: an Overlord RAT loader written in Go that pulls its C2 address from Solana transactions, a Node.js stealer called movinlike targeting Discord, browsers, Telegram and crypto wallets, and a downloader. Three packages (function-flag, function-color, cdn-img-fetch) are described as still live at publication, and function-color carries no payload of its own but lists function-flag as a dependency.

Why it matters

Check your package-lock.json or node_modules for function-flag, function-color, and cdn-img-fetch before your next build — function-color is the trap, since it looks clean but pulls the malicious function-flag in as a dependency, and its postinstall hook fires on install. The mechanism is lifecycle hooks (postinstall), so installing with --ignore-scripts in CI or local installs would break the chain, and version pinning matters because each function-flag version served a payload from a different location.

Discussion angle

Walk through the dependency-chain blind spot: function-color embeds no malicious code, so a naive scan of it passes, yet it pulls function-flag which runs example.js from postinstall. Ask the room how many of them review transitive dependencies versus only the package they explicitly typed into npm install.

Top