Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

MALFEX npm Supply‑Chain Attack Deploys Overlord RAT, Harvests Discord & Browser Data

MALFEX published malicious npm packages that install the Overlord Windows RAT, stealing Discord tokens and browser cookies. The breach underscores the importance of continuous third‑party risk monitoring and audit‑ready evidence of supply‑chain controls.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
hackread.com

MALFEX npm Supply‑Chain Attack Deploys Overlord RAT, Harvests Discord & Browser Data

What Happened — Threat‑intel firm CloudSEK reported that a threat actor group dubbed MALFEX published malicious npm packages that, when installed, drop the Overlord Windows Remote Access Trojan. The RAT exfiltrates Discord authentication tokens, browser cookies, and other credential stores from compromised machines.

Why It Matters for Trust & Control Assurance

  • The incident exemplifies a supply‑chain breach that bypasses traditional perimeter defenses, highlighting the need for continuous third‑party risk monitoring and evidence of vendor oversight.
  • Demonstrates how a missing control around package‑registry vetting can lead to data‑exfiltration, undermining audit‑ready evidence of secure software‑supply‑chain practices.

Who Is Affected – Primarily Windows users of consumer‑grade software who install npm packages, spanning developers, small‑business IT environments, and any organization that allows npm‑based tooling on employee workstations.

Recommended Actions

  • Map the “vendor risk assessment and continuous monitoring” control to your audit framework and collect evidence of npm registry vetting processes.
  • Implement strict allow‑list policies for npm packages, enforce code‑signing verification, and monitor for anomalous process creation linked to Node.js runtimes.

Technical Notes – The malicious packages exploit npm’s open‑publish model; once installed, they execute a PowerShell payload that downloads the Overlord RAT from a C2 server. The RAT harvests Discord tokens via the local Local Storage files and extracts browser cookies from Chrome/Edge profiles. Source: HackRead

📰 Original Source
https://hackread.com/malfex-npm-windows-rat-steals-discord-browser-data/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →