$ techbeacon▋
Threats

Malicious npm Packages Distribute Overlord RAT, Targeting Discord Tokens and Browser Data

Malicious npm Packages Distribute Overlord RAT, Targeting Discord Tokens and Browser Data

Security firm CloudSEK has identified a new supply‑chain campaign that leverages compromised npm packages to install the Overlord remote‑access trojan on Windows computers, stealing Discord authentication tokens and a range of browser credentials.

The attackers uploaded several seemingly innocuous JavaScript libraries to the public npm registry. Each package contains a post‑install script that silently retrieves additional code from a remote server, which in turn drops the Overlord RAT onto the victim’s machine without prompting user interaction.

Overlord is a modular RAT capable of keylogging, screen capture, file exfiltration and command‑and‑control communication over encrypted channels. While the malware family has been observed in previous campaigns, this is the first known instance of it being delivered through the npm ecosystem.

Once active, the trojan scans for Discord token files and browser data stores, extracting session cookies, saved passwords and autofill entries. The harvested information is then sent to command‑and‑control endpoints controlled by the threat actors, enabling them to hijack user accounts and potentially conduct further phishing or fraud operations.

CloudSEK’s investigation uncovered at least four malicious packages that were published over a two‑week window in early July. The packages were removed from npm after the firm reported the abuse, but the researchers estimate that thousands of systems may have been compromised before the takedown. Hackread was the first media outlet to publish details of the operation.

The incident adds to a growing list of supply‑chain attacks targeting JavaScript’s package manager, a trend highlighted by high‑profile breaches such as the 2018 event‑stream compromise and the more recent malicious activesupport modules. npm’s open‑source model, while fostering rapid development, also creates a low‑cost entry point for attackers seeking to reach a broad user base.

Experts advise developers to audit dependencies, enable two‑factor authentication on npm accounts, and monitor install scripts for unexpected network activity. End users should keep operating systems and security software up to date, and consider restricting the execution of post‑install scripts where feasible.

CloudSEK says it will continue to monitor the npm registry for similar threats and work with the platform’s maintainers to improve vetting processes. As supply‑chain tactics evolve, the security community emphasizes the need for heightened vigilance across the entire software development lifecycle.

Source: Hackread
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related