Threats & Adversaries · Supply Chain

MALFEX npm Packages Put Build Hosts at Risk

CloudSEK and Checkmarx tied the MALFEX npm campaign to eight malicious packages that were downloaded 40,767 times and still had live listings in some cases. The packages were published over time under 12 names and were used to deliver Overlord RAT, a Node.js stealer called movinlike, and a downloader.

The malware runs during npm install, using package lifecycle hooks so the code executes as soon as a developer or build host adds the dependency. Some packages fetch a Windows executable or a second-stage payload from a remote server, which means the compromise can happen before any application code is run or reviewed.

For teams that install third-party npm packages on Windows workstations or CI/CD hosts, the exposure sits in the dependency-install path itself. As long as those installs are allowed, live malicious packages can keep extending the blast radius to new machines even if the final shipped app looks clean.

1 source · 14h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: MALFEX npm Packages Put Build Hosts at Risk

More from today