← Back to blog

Malicious npm Packages Spread RATs and Stealers

A prolonged npm supply chain attack distributed malware through 12 packages, 8 of which were actively malicious. These packages delivered info stealers and remote access trojans to unsuspecting developers.

TL;DR

  • Cybercriminals published 12 npm packages since August 2023.
  • Eight of these packages were confirmed to deliver malware.
  • Over 40,000 downloads occurred before detection.
  • Payloads included Overlord RAT and credential stealers.
  • Attack targets developers and CI/CD environments.

Security researchers have uncovered an ongoing supply chain attack within the npm ecosystem, where attackers published multiple packages designed to compromise developer systems. Dubbed 'MALFEX,' this campaign has been active since mid-2023 and highlights persistent risks in open-source software distribution.

The threat actor behind MALFEX is believed to be a single individual who leveraged npm's trust model to distribute malware-laden packages. Once installed, these packages deploy Remote Access Trojans (RATs) and information-stealing payloads like Overlord, posing significant risk to development environments and enterprise networks.

Campaign Overview

  • The campaign was independently discovered by CloudSEK and Checkmarx.
  • It involved 12 total packages, with 8 delivering malicious payloads.
  • Over 40,767 downloads of infected packages were recorded.
  • Packages mimicked legitimate tools to avoid suspicion.
  • Infection vector primarily targets Node.js projects and build pipelines.

Security Implications

  • Supply chain attacks exploit trust in package repositories.
  • Automated dependency installation increases exposure risk.
  • Organizations using affected packages should audit their systems.
  • Developers urged to verify package integrity and maintain updated tooling.
  • Continuous monitoring for anomalous behavior post-installation recommended.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Malicious npm Packages Spread RATs and Stealers — Agent Breach Blog | Agent Breach