MALFEX is an npm software supply-chain malware operation associated with publisher activity dating to August 2023. It uses multiple publisher accounts under Malfex branding, including the self-described Malfex team, to distribute malicious packages alongside benign cover packages. Its malware targets Windows systems through opportunistic package installation and dependency loading. No specific geographic or organizational targeting has been established, and Portuguese-language branding does not establish the operator's country of origin. The operation uses three independent delivery paths: an Overlord remote-access trojan chain, a movinlike information-stealer chain, and a separate downloader chain. Malicious npm lifecycle hooks retrieve and execute payloads, while dependency wrappers also trigger malware when packages are loaded. Delivery techniques include executables disguised as images, encrypted payloads appended to image files, obfuscated JavaScript, and a signed AutoIt interpreter executing encrypted scripts. Concealment measures include excessive whitespace, suppressed errors, deletion of installation scripts, and hidden execution windows. The Overlord chain establishes recurring scheduled-task persistence and provides screenshots, keylogging, clipboard capture, active-window monitoring, file search, remote shell access, and hidden-desktop functionality. Its loader contains process-hollowing and parent-process-spoofing logic. Overlord also supports retrieving command-and-control information from Solana transaction memos, although that functionality was not configured in the analyzed build. Movinlike injects startup code into Discord clients to steal authentication tokens and account information. It also collects browser passwords and cookies, Telegram session data, and cryptocurrency-wallet data. Stolen information is compressed, divided into chunks, and exfiltrated through a Discord webhook. The separate downloader retrieves and silently launches Windows executables, but its unrecovered payload cannot be identified as either Overlord or movinlike. Package download totals measure distribution reach rather than confirmed compromises.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A long-running npm supply-chain activity cluster, assessed to be operated by a lone actor, distributing RATs and information stealers to Windows hosts. Eight identified malicious packages accumulated 40,767 downloads, predominantly through function-flag. Targeting is described as global and opportunistic. Portuguese-language material and Brazilian-associated account details provide attribution clues but do not establish the operator's nationality or targeting of Brazil.
An apparently single-operator activity cluster distributing Windows malware through malicious npm packages since August 2023. The report attributes twelve packages to the operator: eight malicious and four benign cover packages. Three independent delivery paths deploy Overlord RAT, the movinlike information stealer, or an unrecovered payload through function-flag. The malicious packages recorded 40,767 downloads, which do not establish the number of compromised hosts. No geographic or organizational targeting was identified, and no evidence linked the unrecovered function-flag payload to movinlike.
A single-operator activity cluster distributing malicious npm packages to compromise Windows systems. Its delivery chains deploy Overlord RAT for remote access and surveillance, or steal Discord tokens, browser credentials and cookies, cryptocurrency wallet data, and Telegram session data. Connected malicious dependencies and external payloads can remain available after individual packages are removed.
A long-running npm supply-chain operator using burner publisher accounts to distribute malicious packages through two delivery arms. One arm deploys an AutoIt/IExpress loader chain for a modified Overlord Go RAT with a live Solana-based C2 resolver; the other delivers the movinlike Node.js information stealer, which targets Discord clients, browser data, and Telegram tdata and exfiltrates through Discord webhooks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.