Supply‑Chain Attack Hits npm: Eight Malicious Packages Spread Overlord RAT to Over 40,000 Users
Security researchers have uncovered a sustained supply‑chain campaign that leveraged eight compromised packages on the npm registry, amassing more than 40,000 downloads before being taken down. The packages silently installed the Overlord remote‑access trojan and a credential‑stealing payload on any system that installed them, turning ordinary development environments into footholds for attackers.
The operation, dubbed “MALFEX” by cybersecurity firms CloudSEK and Checkmarx, represents one of the more extensive npm‑based malware distributions seen to date. By masquerading as legitimate JavaScript libraries, the malicious modules slipped past npm’s automated checks and were published to the public registry, where developers worldwide fetched them as dependencies for their own projects.
Supply‑chain attacks of this nature exploit the trust developers place in third‑party code. Once a compromised package is installed, its post‑install script can execute arbitrary commands, download additional components, and establish persistent back‑doors. In the MALFEX case, the Overlord RAT provided attackers with full control over infected hosts, while the accompanying stealer harvested credentials, API keys, and other sensitive data.
Industry analysts note that the sheer volume of downloads—over 40,000 installations—highlights the broad reach of npm as a software ecosystem and the potential impact of a single malicious package. The incident underscores the need for stricter vetting of dependencies, adoption of lock‑file integrity checks, and continuous monitoring for anomalous behavior in build pipelines.
CloudSEK and Checkmarx have issued advisories urging developers to audit their dependency trees, remove any of the identified malicious packages, and rotate credentials that may have been exposed. npm has responded by removing the offending modules and pledging to enhance its security tooling. As supply‑chain threats continue to evolve, experts say the community must adopt a “zero‑trust” stance toward third‑party code to mitigate future attacks.
Comments (0)
Be the first to comment.
Join the discussion