npm Ecosystem — Supply Chain Campaign Delivers Overlord RAT via Eight Malicious Packages (CVE-2026-60137)
Publication date: October 07, 2026
Category: Supply Chain / Malware
Introduction
Cybersecurity researchers have disclosed technical details regarding a long-running supply chain campaign within the npm package repository that directly targets developers and Windows environments through the stealthy deployment of information stealers and remote access trojans (RATs). Codenamed MALFEX by researchers at CloudSEK and Checkmarx, the malicious activity is attributed to a single Portuguese-speaking threat actor who published 12 packages starting in August 2023, eight of which have been officially flagged as malicious. Additionally, related infrastructure shares operational overlaps with campaigns exploiting critical vulnerabilities in web applications, such as the SQL injection flaw in WordPress tracked as CVE-2026-60137.
What is MALFEX and the Compromised npm Ecosystem? (General Analysis)
The Node Package Manager (npm) ecosystem remains a frequent vector for software supply chain attacks due to the inherent trust developers place in third-party dependencies. The MALFEX campaign exploits this trust by embedding malicious routines directly inside the lifecycle hooks (specifically postinstall) of packages disguised as innocuous utility tools.
The gravity of this incident lies in its automated scale: with over 40,000 combined downloads—led primarily by the function-flag package accounting for more than 37,000 installations—the threat quietly infiltrates local development workspaces and build pipelines. Notably, capabilities associated with the distributed RAT (Overlord RAT) intersect with web exploitation vectors like SQL injection in content management systems. Official NVD records for related flaws help frame the broader threat landscape:
- CVE-2026-60137 (Confirmed NVD Data): An SQL injection vulnerability (CWE-89) in WordPress caused by improper sanitization of the
author__not_inparameter inWP_Query. It carries a CVSS v3.1 base score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N, rated MEDIUM, and included in the CISA KEV catalog).
How Does It Work? (Technical Analysis)
The operational mechanism of the MALFEX infrastructure relies on multiple infection pathways aimed at Windows systems, incorporating clever staging and execution techniques:
- Initial Infection and Lifecycle Hooks: Malicious packages (including
tlxbnhd,tldriver,mxdriver,img-to-native,native-runner,function-flag,function-color, andcdn-img-fetch) leverage post-install scripts. For instance, in version 1.7.3 offunction-flag, the postinstall script executes an auxiliary JavaScript file that calls an ASCII art function using the Bloody font. This hidden routine automatically communicates with a Brazilian application hosting service (cdnzona.discloud.app) to download a renamed legitimate Node.js binary (node.exe), saves it persistently to%APPDATA%\node.exe, and runs it with a hidden window. - Payload Delivery Vectors:
- Overlord RAT Loaders: Three packages (
tlxbnhd,tldriver,mxdriver) act as direct loaders for Overlord, an open-source RAT written in Go that utilizes Solana blockchain transactions to dynamically extract its command-and-control (C2) address. - Information Stealers: A secondary infection chain installs
movinlike, a Node.js-based stealer engineered to harvest sensitive data from Discord clients, web browsers, Telegram, and cryptocurrency wallets. - Dynamic Chaining: Packages like
function-colorcontain no internal payload of their own but declarefunction-flagas a dependency, guaranteeing execution when installed.
- Overlord RAT Loaders: Three packages (
Affected Systems / Environments
This campaign directly impacts development environments, developer workstations, and continuous integration (CI/CD) pipelines utilizing Node.js (npm), alongside web servers running vulnerable content management versions associated with secondary actor clusters.
| CVE / Component | Category (CWE) | Impact | CVSS | Vector (Summary) |
|---|---|---|---|---|
| CVE-2026-60137 | CWE-89 (SQL Injection) | High confidentiality impact on vulnerable backend apps | 5.9 | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Malicious npm Packages | CWE-506 (Embedded Malicious Code) | Remote code execution, credential theft, and RAT deployment | Estimated: 8.8 | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Mitigation and Detection
Remediation
- Dependency Auditing: Immediately perform dependency audits and vulnerability scans across projects utilizing tools like
npm auditor Software Composition Analysis (SCA) platforms. - Script Execution Restrictions: Enforce the
--ignore-scriptsflag during npm installations within production or CI/CD environments to prevent automatic execution of malicious post-install lifecycle hooks. - Patching and Updates: Update vulnerable web components and software frameworks in accordance with official vendor advisories (such as patches addressing SQL injection in CVE-2026-60137).
Detection
- Process and Artifact Monitoring: Inspect user profile directories for anomalous binary placements, such as
%APPDATA%\node.exe, or suspicious child process spawning originating from Node execution trees. - Indicators of Compromise (IoCs): Monitor network telemetry for outbound connections to unverified application hosting services or unusual transactional queries targeting the Solana network utilized by the Overlord RAT for C2 routing.
“The weaponization of postinstall hooks in public repositories demonstrates that blind trust in open-source dependencies remains a critical supply chain attack vector, necessitating strict pipeline hardening.”
Wrapping Up
The MALFEX campaign highlights the continuous evolution of software supply chain attacks leveraging public repositories like npm. With over 40,000 downloads spread across eight malicious packages, the adversary successfully deployed advanced espionage tooling, including the Overlord RAT and the movinlike stealer. Correlating these tactics with broader infrastructure flaws emphasizes the vital need for robust defensive controls spanning both developer workstations and exposed web servers.
References
- CloudSEK. (2026). Malfex: Malicious npm postinstall supply chain campaign. Retrieved from https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
- Checkmarx. (2026). Malfex npm malware campaign: Three payloads and an adversary that signs their work. Retrieved from https://checkmarx.com/zero-post/malfex-npm-malware-campaign-three-payloads-and-an-adversary-that-signs-their-work/
- GitHub. (n.d.). Overlord RAT repository. Retrieved from https://github.com/vxaboveground/Overlord
- Jamf. (2026). Fake Zoom installer delivers Overlord RAT macOS. Retrieved from https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
- National Vulnerability Database (NVD). CVE-2026-60137 Detail. U.S. National Institute of Standards and Technology (NIST). Available at: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf and https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137