Hackread MALFEX Campaign Targets npm with Windows RAT and Data Theft
Article Content
- •The MALFEX campaign has been active since August 2023, using malicious npm packages.
- •The Overlord RAT is delivered through a Windows executable disguised as a PNG file.
- •Three malicious npm packages remain active, posing ongoing risks to users.
The MALFEX campaign, uncovered by CloudSEK, has been active since August 2023, using malicious npm packages to deploy the Overlord RAT and steal data from Windows systems. The operator, identified as Portuguese-speaking, has uploaded at least 12 npm packages and a GitHub repository linked to the operation. The attack involves two delivery chains: one that downloads a Windows executable disguised as a PNG file to install the Overlord RAT, and another that retrieves a Node.js bundle to steal Discord tokens and browser data. Three malicious packages remain active, including function-flag, which has been continuously malicious since July 2025. The campaign highlights ongoing vulnerabilities in the npm ecosystem, with some malicious packages still available despite advisories. Defenders are advised to block specific packages and monitor for persistence artifacts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Shai-hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which npm packages are affected?
Is the MALFEX campaign still active?
What actions should defenders take?
Continue Reading
North Korean Hackers Deploy Mac Backdoors via Fake Job Tests Targeting IT Firms North Korean threat actor Jade Sleet, also known as TraderTraitor, has been linked to a breach of an Indian IT services provider using macOS backdoors named FLATROOF and ROOFDECK. The attack involved social engineering tactics, where fake job interview assignments were used to lure DevOps engineers into executing…
UAC-0099 Uses GuardBreaker to Evade AI Malware Detection Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download…