Skip to content
MALFEX Campaign Targets npm with Windows RAT and Data Theft

MALFEX Campaign Targets npm with Windows RAT and Data Theft

First seen 30 Sep 2026, 23:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 00:01 UTC
  • •The MALFEX campaign has been active since August 2023, using malicious npm packages.
  • •The Overlord RAT is delivered through a Windows executable disguised as a PNG file.
  • •Three malicious npm packages remain active, posing ongoing risks to users.

The MALFEX campaign, uncovered by CloudSEK, has been active since August 2023, using malicious npm packages to deploy the Overlord RAT and steal data from Windows systems. The operator, identified as Portuguese-speaking, has uploaded at least 12 npm packages and a GitHub repository linked to the operation. The attack involves two delivery chains: one that downloads a Windows executable disguised as a PNG file to install the Overlord RAT, and another that retrieves a Node.js bundle to steal Discord tokens and browser data. Three malicious packages remain active, including function-flag, which has been continuously malicious since July 2025. The campaign highlights ongoing vulnerabilities in the npm ecosystem, with some malicious packages still available despite advisories. Defenders are advised to block specific packages and monitor for persistence artifacts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-08-01
MALFEX campaign begins
The operator starts uploading malicious npm packages under Portuguese-language accounts.
Cloudsek
2025-07-18
function-flag becomes malicious
The npm package function-flag has been continuously malicious since this date.
Cloudsek
2026-09-28
Official advisory published
An advisory reflects the operator's identity and links to the malicious packages.
Cloudsek

More articles in this cluster (2)

Following this threat?

Track Shai-hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which npm packages are affected?
The affected packages include function-flag, cdn-img-fetch, and function-color.
Is the MALFEX campaign still active?
Yes, the campaign continues to pose a threat with several malicious packages still available.
What actions should defenders take?
Defenders should block the installation of specific malicious packages and monitor for related persistence artifacts.