Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
- ID
- 32900
- Status
- summarized
- Published
- 08 Oct 2026, 1:43 AM
- Fetched
- 08 Oct 2026, 2:58 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 08 Oct 2026, 2:59 AM
- Tags
- Audience
- developersvibe_coders
What happened
CloudSEK and Checkmarx disclosed MALFEX, an npm supply-chain campaign attributed to a lone actor who has published 12 packages since August 2023, eight of them flagged malicious: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch. The packages have 40,767 total downloads, 37,419 of which come from function-flag alone (first published July 2024, latest version August 4, 2025), and they deliver three payload paths: an Overlord RAT loader written in Go that pulls its C2 address from Solana transactions, a Node.js stealer called movinlike targeting Discord, browsers, Telegram and crypto wallets, and a downloader. Three packages (function-flag, function-color, cdn-img-fetch) are described as still live at publication, and function-color carries no payload of its own but lists function-flag as a dependency.
Why it matters
Check your package-lock.json or node_modules for function-flag, function-color, and cdn-img-fetch before your next build — function-color is the trap, since it looks clean but pulls the malicious function-flag in as a dependency, and its postinstall hook fires on install. The mechanism is lifecycle hooks (postinstall), so installing with --ignore-scripts in CI or local installs would break the chain, and version pinning matters because each function-flag version served a payload from a different location.
Discussion angle
Walk through the dependency-chain blind spot: function-color embeds no malicious code, so a naive scan of it passes, yet it pulls function-flag which runs example.js from postinstall. Ask the room how many of them review transitive dependencies versus only the package they explicitly typed into npm install.