HackerFeeds

CyberSecurity News

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News
· October 7, 2026

AI summary

Cybersecurity researchers have uncovered a malware campaign targeting npm that delivers information stealers and remote access trojans to compromised systems. The campaign, dubbed MALFEX, is believed to be the work of a single threat actor who has published 12 packages since August 2023. Eight of these packages have been identified as malicious and have been downloaded a total of 40,767 times. The malicious packages are designed to push Overlord RAT and stealer to compromised hosts. The researchers from CloudSEK and Checkmarx have disclosed details of this long-running supply chain malware campaign.

Read the full article at The Hacker Newsthehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.