MALFEX npm supply-chain malware campaign
Campaign
Summary
Hide ▲
Show ▼
A long-running npm supply-chain campaign named MALFEX is pushing information stealers and remote access trojans (RATs) to compromised Windows hosts. The operation has used 12 published packages since August 2023, with 8 flagged as malicious, and the packages have already been downloaded 40,767 times. Researchers also found multiple delivery paths that load Overlord RAT, a movinlike stealer, and a downloader, showing an active package-based operation with broad opportunistic reach.
Related Happenings
WeaselBiscuit stealer delivered via 13 npm packages
Malware Activity
H score30
First: 18.09.2026 13:40
Last: 18.09.2026 13:40
Sources 1
About this happening:
The WeaselBiscuit stealer was found in 13 npm packages, expanding supply-chain risk to developer environments and extension data theft. The malware is triggered by an npm...
WeaselBiscuit stealer delivered via 13 npm packages
Malware ActivityAbout this happening: The WeaselBiscuit stealer was found in 13 npm packages, expanding supply-chain risk to developer environments and extension data theft. The malware is triggered by an npm...
SuccessKey ViteVenom ChainVeil supply-chain campaign targeting Vite developers
Campaign
H score8
First: 17.07.2026 21:54
Last: 17.07.2026 21:54
Sources 1
About this happening:
The SuccessKey-linked ViteVenom campaign is targeting Vite developers with seven malicious npm packages and a blockchain-based C2 path that delivers a RAT....
SuccessKey ViteVenom ChainVeil supply-chain campaign targeting Vite developers
CampaignAbout this happening: The SuccessKey-linked ViteVenom campaign is targeting Vite developers with seven malicious npm packages and a blockchain-based C2 path that delivers a RAT....
UAT-11795 trojanized installer campaign targeting users across multiple countries
Campaign
H score35
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...
UAT-11795 trojanized installer campaign targeting users across multiple countries
CampaignAbout this happening: The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...
UAT-11795 Starland RAT trojanized installer malware activity
Malware Activity
H score31
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
UAT-11795 Starland RAT trojanized installer malware activity
Malware ActivityAbout this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Timeline
-
07.10.2026 20:43 1 articles · 2h ago
function-flag 1.7.3 hides a payload download in postinstall
Technical Analysis UpdateThe npm package function-flag version 1.7.3, released on August 4, 2025, runs example.js through a postinstall flow, calls the package's ASCII art function with the Bloody font, and triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, saves it to %APPDATA% ode.exe, and launches it with its window hidden.
Show sources
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer — thehackernews.com — 07.10.2026 20:43
-
07.10.2026 20:43 2 articles · 2h ago
Researchers disclose MALFEX npm supply-chain malware campaign
Initial DisclosureCloudSEK and Checkmarx disclosed MALFEX, a long-running npm supply-chain malware campaign that used 12 packages to deliver Overlord RAT loaders, a movinlike Node.js stealer, and a downloader to Windows systems; the packages were collectively downloaded 40,767 times, and eight of the 12 packages were flagged as malicious.
Show sources
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer — thehackernews.com — 07.10.2026 20:43
- Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer — thehackernews.com — 07.10.2026 20:43