Find notable cyber news and cases, enriched with sources, timelines, and signals.

MALFEX npm supply-chain malware campaign

Campaign
First reported
Last updated
Happening score
H score 12
1 unique sources, 1 articles

Summary

Hide ▲

A long-running npm supply-chain campaign named MALFEX is pushing information stealers and remote access trojans (RATs) to compromised Windows hosts. The operation has used 12 published packages since August 2023, with 8 flagged as malicious, and the packages have already been downloaded 40,767 times. Researchers also found multiple delivery paths that load Overlord RAT, a movinlike stealer, and a downloader, showing an active package-based operation with broad opportunistic reach.

Related Happenings

WeaselBiscuit stealer delivered via 13 npm packages

Malware Activity
H score30 First: 18.09.2026 13:40 Last: 18.09.2026 13:40 Sources 1

About this happening: The WeaselBiscuit stealer was found in 13 npm packages, expanding supply-chain risk to developer environments and extension data theft. The malware is triggered by an npm...

SuccessKey ViteVenom ChainVeil supply-chain campaign targeting Vite developers

Campaign
H score8 First: 17.07.2026 21:54 Last: 17.07.2026 21:54 Sources 1

About this happening: The SuccessKey-linked ViteVenom campaign is targeting Vite developers with seven malicious npm packages and a blockchain-based C2 path that delivers a RAT....

UAT-11795 trojanized installer campaign targeting users across multiple countries

Campaign
H score35 First: 16.07.2026 13:19 Last: 16.07.2026 13:19 Sources 1

About this happening: The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...

UAT-11795 Starland RAT trojanized installer malware activity

Malware Activity
H score31 First: 16.07.2026 13:19 Last: 16.07.2026 13:19 Sources 1

About this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Timeline

  1. 07.10.2026 20:43 1 articles · 2h ago

    function-flag 1.7.3 hides a payload download in postinstall

    Technical Analysis Update

    The npm package function-flag version 1.7.3, released on August 4, 2025, runs example.js through a postinstall flow, calls the package's ASCII art function with the Bloody font, and triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, saves it to %APPDATA% ode.exe, and launches it with its window hidden.

    Show sources
  2. 07.10.2026 20:43 2 articles · 2h ago

    Researchers disclose MALFEX npm supply-chain malware campaign

    Initial Disclosure

    CloudSEK and Checkmarx disclosed MALFEX, a long-running npm supply-chain malware campaign that used 12 packages to deliver Overlord RAT loaders, a movinlike Node.js stealer, and a downloader to Windows systems; the packages were collectively downloaded 40,767 times, and eight of the 12 packages were flagged as malicious.

    Show sources