MALFEX npm Supply‑Chain Attack Deploys Overlord RAT, Harvests Discord & Browser Data
What Happened — Threat‑intel firm CloudSEK reported that a threat actor group dubbed MALFEX published malicious npm packages that, when installed, drop the Overlord Windows Remote Access Trojan. The RAT exfiltrates Discord authentication tokens, browser cookies, and other credential stores from compromised machines.
Why It Matters for Trust & Control Assurance
- The incident exemplifies a supply‑chain breach that bypasses traditional perimeter defenses, highlighting the need for continuous third‑party risk monitoring and evidence of vendor oversight.
- Demonstrates how a missing control around package‑registry vetting can lead to data‑exfiltration, undermining audit‑ready evidence of secure software‑supply‑chain practices.
Who Is Affected – Primarily Windows users of consumer‑grade software who install npm packages, spanning developers, small‑business IT environments, and any organization that allows npm‑based tooling on employee workstations.
Recommended Actions
- Map the “vendor risk assessment and continuous monitoring” control to your audit framework and collect evidence of npm registry vetting processes.
- Implement strict allow‑list policies for npm packages, enforce code‑signing verification, and monitor for anomalous process creation linked to Node.js runtimes.
Technical Notes – The malicious packages exploit npm’s open‑publish model; once installed, they execute a PowerShell payload that downloads the Overlord RAT from a C2 server. The RAT harvests Discord tokens via the local Local Storage files and extracts browser cookies from Chrome/Edge profiles. Source: HackRead