Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.

supply chain threat

Malicious packages published as part of a long-running NPM supply chain campaign have accumulated over 40,000 downloads, Checkmarx reports.

Dubbed MALFEX and distributing malware such as the Overlord RAT and infostealers, the campaign has been ongoing since August 2023, when the threat actor published its first package.

To date, the threat actor has published 12 packages, eight of which are malicious. Five have been removed from the registry, but three were still installable as of October 1, namely function-flag, function-color, and cdn-img-fetch.

According to Checkmarx, function-flag deserves special attention: it has been malicious since July 2025, has more than 37,000 downloads, and no advisory flags it as malicious.

Open Source Vulnerabilities (OSV) advisories have been published for six malicious packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch. However, the entry for cdn-img-fetch covers only two of its four malicious iterations.

Checkmarx identified three independent delivery paths used in the campaign, noting that they do not share infrastructure, although they are linked to the same threat actor.

Advertisement. Scroll to continue reading.

The first involves loaders for the Overlord RAT and obfuscated scripts executed during npm install. While the scripts can be launched on Windows, macOS, and Linux, the payload only works on Windows systems.

The Overlord RAT provides the operator with monitoring and control capabilities, including screen capture, keylogging, window monitoring, remote shell access, file search, and a hidden desktop to perform malicious activities without detection.

As part of the second path, malicious code is executed when the package is loaded, to drop the Node.js information stealer ‘movinlike’ on the victims’ machines. The malware targets eight Discord clients, seven popular browsers, and cryptocurrency wallets for data theft.

The third path is the longest-running part of the campaign. It involves a separate downloader in each malicious version of function-flag, designed to fetch a payload from a different location.

According to Checkmarx, the infection routine is implemented so that the package installation could complete even if the payload download fails. The routine fails silently on macOS and Linux, meaning that only Windows systems are affected.

“No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target,” Checkmarx notes.

Related: Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.