As reported by The Hacker News, researchers at CloudSEK and Checkmarx have detailed a sustained npm supply chain campaign—codenamed MALFEX—that distributed remote access trojans and information stealers through at least eight malicious packages totaling over 40,000 downloads since mid-2023. What deserves attention is not just the volume but the operational maturity displayed by what appears to be a single actor.

Threat Alert: Supply chain attacks on package registries are no longer novel.

Why This Campaign Is Different

Supply chain attacks on package registries are no longer novel. What distinguishes MALFEX is the deliberate layering of payloads and the use of blockchain-derived C2 infrastructure. The Overlord RAT reportedly resolves its command-and-control address through Solana transactions—an approach that makes infrastructure takedown significantly harder because the address is not statically embedded and can be rotated without redeploying the payload.

The actor also demonstrated patience. Publishing since August 2023 and iterating versions through August 2025 indicates a long-term monetization strategy rather than a smash-and-grab operation. The Portuguese-language artifacts and Brazilian hosting infrastructure suggest a specific regional focus, but npm packages are global by default—any developer who pulled these dependencies is exposed regardless of geography.

Payload Chain Analysis

  • Overlord RAT loaders — tlxbnhd, tldriver, and mxdriver use lifecycle hooks to fetch and execute a Windows binary.
  • movinlike stealer chain — img-to-native pulls cdn-img-fetch to retrieve a Go executable that then deploys a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets.
  • function-flag — the highest-volume package (37,419 downloads) uses postinstall hooks with per-version payload locations, complicating static blocklisting.
  • function-color — dependency-based trigger; no embedded payload but pulls function-flag and activates hidden routines through ASCII font selection.

The font-based trigger mechanism in function-color is particularly noteworthy. Using an ASCII art library's Bloody font value as an activation condition is a form of environmental keying that evades sandbox detonation—automated analysis systems are unlikely to select that specific parameter combination.

Broader Implications

The fact that three packages remain live at time of reporting underscores a persistent gap: registry maintainers cannot match the speed at which sophisticated actors iterate malicious versions.

The report also links Overlord RAT to separate campaigns exploiting WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137, known as wp2shell) and a macOS fake Zoom lure. This cross-platform reuse suggests the RAT is being offered or shared among multiple operators, expanding its reach well beyond the initial npm vector.

For development organizations, the lesson is that package popularity is not validation. function-flag accumulated legitimate-looking download volume through dependency propagation and time—exactly the signals that naive trust scoring rewards.

Shield53 Recommendations

  • Immediate audit: Search package manifests across all repositories for tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch. Remove and investigate any matches.
  • Disable postinstall by policy: Enforce npm config set ignore-scripts true in CI environments and require manual review of install scripts for approved packages only.
  • Implement runtime EDR on developer workstations: The payloads target Windows specifically. Ensure endpoint detection covers unexpected node.exe execution from %APPDATA% and outbound connections to hosting services like discloud.app.
  • Adopt provenance tooling: Use npm audit signatures, Sigstore-based signing, and dependency pinning with lockfile integrity verification to reduce substitution risk.
  • Hunt for post-compromise indicators: If any flagged package was used in production, assume credential compromise. Rotate Discord tokens, browser-stored credentials, Telegram sessions, and cryptocurrency wallet seeds. The movinlike stealer specifically targets these stores.
  • Monitor Solana transaction patterns: If your threat hunting team can access blockchain analytics, look for transactions that encode C2 addresses—this technique will likely proliferate to other malware families.

The npm ecosystem remains a soft target. Until registry-level signing and behavioral analysis become default, the burden falls on development teams to treat every dependency as untrusted code executing with their privileges.