Malicious npm packages deliver Overlord RAT and stealer
Researchers have uncovered a prolonged npm supply chain malware campaign dubbed MALFEX, delivering the Overlord remote access trojan and a data stealer targeting Windows systems. Eight identified packages, collectively downloaded over 40,000 times, infected machines mainly through postinstall scripts and dependency chains. The most downloaded package, "function-flag," was first published in July 2024. Three packages remain live as of the latest report.
- Eight malicious npm packages identified
- Over 40,000 cumulative downloads
- Main payloads are Overlord RAT and a Node.js stealer
- Three packages still available for download
- Attack targets Windows through multiple infection chains
Sources covering this
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.