Back to Newsroom
Threat Intel

Malicious npm Packages Deliver Overlord RAT in 40,000+ Download Supply-Chain Campaign

Researchers uncovered a year-long npm supply-chain campaign using eight malicious packages — downloaded over 40,000 times — to plant the Overlord RAT and a Node.js credential stealer on Windows systems.

Malicious npm Packages Deliver Overlord RAT in 40,000+ Download Supply-Chain Campaign

Lead

A long-running npm supply-chain campaign has been pushing malware to Windows developers through eight malicious packages that have racked up more than 40,000 downloads combined.

What happened

Security researchers traced the operation to a single threat actor who has published a dozen npm packages since August 2023, eight of which turned out to be malicious. The packages split into two delivery chains:

  • Three loaders (tlxbnhd, tldriver, mxdriver) ship an installer script that fetches a disguised Windows executable, unpacks it through a signed self-extracting archive, and uses a scripting-language loader to hollow out a legitimate Windows process before launching the Overlord RAT — an open-source remote access trojan written in Go that resolves its command-and-control address from memos stored on the Solana blockchain.
  • A second chain, anchored by the packages img-to-native and cdn-img-fetch, decodes a payload smuggled inside what looks like an ordinary PNG image, then drops a Go-based downloader that in turn installs a Node.js credential stealer capable of raiding Discord, half a dozen browsers, Telegram, and cryptocurrency wallets.

A third package, function-flag, accounted for the bulk of the activity — more than 37,000 of the 40,767 total downloads. Its postinstall script quietly triggers a hidden download routine once a particular font value is referenced in an ASCII-art helper function, pulling a second-stage payload from a Brazilian hosting provider. A companion package, function-color, carries no payload of its own but lists function-flag as a dependency, pulling it in automatically.

npm has since pulled img-to-native, cutting off one of the two delivery arms, but several of the identified packages — including function-flag, function-color, and cdn-img-fetch — were still live and installable as of this writing.

Clues in the operator's tooling — Portuguese-language commit messages and project descriptions, a Brazilian hosting footprint, and a Brazilian-handle GitHub identity — point to a Portuguese-speaking actor, though researchers are careful to note that says nothing about who the campaign actually targets: npm and Discord give it global reach regardless of where the operator is based.

The Overlord RAT itself isn't new to this campaign. It has separately shown up this year in attacks exploiting WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) and in a macOS campaign using a fake Zoom installer that shares infrastructure with a cluster suspected of North Korea-aligned activity — suggesting the RAT is shared tooling rather than evidence of one operator behind every case.

Why it matters

npm's open publishing model means anyone can ship a package under an innocuous name — an image resizer, a driver helper, a UI flag utility — and reach thousands of installs before anyone notices the postinstall hook doing something else entirely. For a Node.js shop, a single npm install run by a developer or a CI pipeline is enough to execute an attacker's code with the privileges of whoever ran it. Stealers that specifically target Discord, Telegram, browsers, and crypto wallets translate directly into account takeover, session-token theft, and financial loss — well beyond a typical "dependency had a bug" story.

What to do

  • Audit your dependency tree for the packages named in this campaign (tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, cdn-img-fetch) and remove them immediately if present, directly or transitively.
  • Treat postinstall/preinstall lifecycle scripts as a standing risk: run npm install --ignore-scripts in CI where feasible, and review any package that still needs install scripts before approving it.
  • Rotate credentials and session tokens for Discord, Telegram, browser-saved logins, and any crypto wallet accessible from a machine that may have run an affected package.
  • Pin dependency versions and use a software composition analysis (SCA) tool that flags newly published or low-reputation packages before they land in a lockfile.
  • If you run internal mirrors or private registries, block the identified package names and watch for re-published variants under similar names.
SHARE