Back to News
Cybersecurity

Malicious npm Packages Discovered: Overlord RAT and Stealer Target Developers

Security researchers reveal a supply chain attack involving npm packages that deliver malware, impacting software developers.

Recent findings from cybersecurity researchers at CloudSEK and Checkmarx have unveiled a persistent npm supply chain attack, codenamed MALFEX, which has successfully distributed eight malicious packages to over 40,000 downloads. These packages are designed to deploy Overlord RAT and information stealers, highlighting the vulnerabilities within the npm ecosystem that can be exploited by threat actors. The investigation suggests that the campaign is likely executed by a single individual who has been active since August 2023, releasing a total of twelve packages, with eight identified as malicious.

For businesses, particularly those in software development, this incident underscores the necessity of robust supply chain security measures. Organizations must implement stringent package management practices, including regular audits of dependencies and the use of tools that can detect malicious code in third-party libraries. This incident serves as a critical reminder that even trusted repositories like npm can harbor threats, emphasizing the importance of vigilance in maintaining the integrity of software supply chains. As cybersecurity threats continue to evolve, organizations should prioritize enhancing their defenses against such sophisticated attacks, particularly in the realm of AI and automated systems that increasingly rely on external code components.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html)*