HackRead

MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data


CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data, and target Windows systems.

A long-running supply-chain campaign has used malicious npm packages to deliver a remote access trojan (RAT), steal credentials and maintain access to compromised Windows systems.

CloudSEK’s Global Threat Intelligence team, which shared its findings with Hackread.com, dubbed the operation MALFEX and linked it to a single operator active since August 2023.

The operator used multiple npm accounts containing the Malfex name, along with a GitHub account called cavecrew. CloudSEK found references to “Murizada” in one package’s README, where the name was listed as the owner of the Malfex team. The researchers linked at least 12 npm packages and a GitHub repository to the operation.

CloudSEK also discovered indications that the operator is Portuguese-speaking, including Portuguese text in a repository and a Brazilian-linked GitHub handle, although the researchers did not link the campaign to Brazil.

One Chain Delivers Overlord RAT

CloudSEK’s research identified packages including tlxbnhd, tldriver and mxdriver using npm installation scripts to download a Windows executable disguised as a PNG file. The file contained an encrypted script that ultimately loaded Overlord RAT, an open-source Go-based RAT.

MALFEX infection chain showing how malicious npm packages ultimately deliver Overlord RAT. (Credit: CloudSEK)

Overlord can capture screens, record keystrokes, provide remote shell access and interact with a victim’s desktop. This version of the malware can use the Solana blockchain to retrieve updated command-and-control (C2) server addresses, allowing the malware to locate its control infrastructure.

Another Chain Steals Discord and Browser Data

A second delivery chain used img-to-native and its dependency cdn-img-fetch to retrieve a PNG file from GitHub. The package decrypted an embedded payload and eventually fetched a 64 MB Node.js bundle.

The bundle injected code into Discord clients and stole Discord authentication tokens and account information. It also targeted browser cookies and credentials, cryptocurrency wallets and Telegram session data. The stolen information was sent to an attacker-controlled Discord webhook.

Malicious Packages Remained Available

Some of the malicious packages remained available long after the campaign began. Five MALFEX packages had received security advisories, while three malicious packages remained without advisories.

One of them, function-flag, remained malicious and installable for 14 months. Another, cdn-img-fetch, remained available after npm removed its parent package, img-to-native. The related function-color package also pulled function-flag as a dependency.

Malicious npm packages and related infrastructure linked to the MALFEX campaign. (Credit: CloudSEK)

The MALFEX findings come amid continued abuse of npm for supply-chain attacks. In August, Hackread.com reported that a Shai-Hulud campaign compromised Keyv and related packages, with the malware spreading to additional npm packages and stealing developer credentials.

CloudSEK warned that removing one malicious npm package is not always enough when related packages, dependencies and external payloads remain active. The researchers recommend checking connected components instead of relying only on individual npm security advisories.





Source link