Recent findings by CloudSEK reveal the MALFEX campaign, which has leveraged compromised npm packages to deploy a remote access trojan known as Overlord RAT, targeting critical user data and Windows systems.
This long-term supply chain attack has seen malicious npm packages used to install a RAT that enables attackers to gain unauthorized access to sensitive information and systems. Through these packages, the campaign has been able to steal login credentials and establish persistence on victimized devices running Windows.
The operation, dubbed MALFEX by CloudSEK’s Global Threat Intelligence team, has been traced back to a single operator who has been active since August 2023. The attackers operated multiple npm accounts associated with the Malfex name, along with a GitHub account named cavecrew. Research indicates that references to the name “Murizada” appear in the documentation of one package, indicating a potential leader within the Malfex operation. A total of at least twelve npm packages and a specific GitHub repository have been linked to this malicious activity.
CloudSEK’s research has also uncovered suggestions that the operator is likely Portuguese-speaking, as evidenced by Portuguese text found in one of the repositories along with a GitHub handle connected to Brazil. Despite these linguistic indicators, there is no direct attribution of the campaign to Brazil itself.
One chain of the campaign has been confirmed to deliver the Overlord RAT, which uses npm installation scripts to download a Windows executable disguised as a PNG file. This executable contains an encrypted script that loads the RAT, which is capable of capturing screen activity, logging keystrokes, providing remote shell access, and interacting with the compromised system’s desktop environment. Notably, this version of Overlord utilizes the Solana blockchain to fetch updated command-and-control server addresses, enhancing the malware’s evasion and persistence strategies.
Another distinct chain associated with MALFEX exploited the npm packages img-to-native and its dependency cdn-img-fetch. This chain was found to retrieve a PNG file from GitHub, which upon decryption executed a substantial Node.js package. This package injected malicious code into Discord clients, allowing for the theft of authentication tokens and sensitive account data. Moreover, it targeted browser cookies and cryptocurrency wallet credentials, routing the collected data to a Discord webhook controlled by the attackers.
Alarming is the fact that some of these malicious packages remained accessible even long after the campaign’s inception. Although five MALFEX packages were warned about via security advisories, three others continued to exist without such warnings. For instance, the package function-flag remained malignant and installable for a period of fourteen months, while cdn-img-fetch stayed available after the removal of its parent package img-to-native. Additionally, the function-color package pulled in function-flag as a dependency, showcasing the challenge of eliminating threats from interconnected packages.
The findings from CloudSEK highlight ongoing vulnerabilities in how npm packages are managed and the potential abuse within supply chain ecosystems. In a recent incident documented in August, Hackread.com reported on the Shai-Hulud campaign which compromised the Keyv package and its dependencies, further demonstrating a trend of malicious actors leveraging npm for supply chain attacks. Industry experts encourage vigilance in monitoring connected components rather than relying solely on advisories regarding individual npm packages. The necessity for a comprehensive approach to security remains imperative for businesses, particularly in safeguarding against evolving threats deployed through packages that may appear harmless at first glance.
In assessing the methodology of the MALFEX campaign, various tactics listed in the MITRE ATT&CK Matrix are relevant, including initial access via software supply chain attacks, persistence through backdoor mechanisms, and credential dumping techniques allowing attackers to maintain control over compromised systems. This framework elucidates a nuanced understanding of the operational tactics employed by cyber adversaries, emphasizing the complexities faced by organizations in their cybersecurity posture.