Malware & Threats

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.

supply chain threat

Malicious packages published as part of a long-running NPM supply chain campaign have accumulated over 40,000 downloads, Checkmarx reports.

Dubbed MALFEX and distributing malware such as the Overlord RAT and infostealers, the campaign has been ongoing since August 2023, when the threat actor published its first package.

To date, the threat actor has published 12 packages, eight of which are malicious. Five have been removed from the registry, but three were still installable as of October 1, namely function-flag, function-color, and cdn-img-fetch.

According to Checkmarx, function-flag deserves special attention: it has been malicious since July 2025, has more than 37,000 downloads, and no advisory flags it as malicious.

Open Source Vulnerabilities (OSV) advisories have been published for six malicious packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch. However, the entry for cdn-img-fetch covers only two of its four malicious iterations.

Checkmarx identified three independent delivery paths used in the campaign, noting that they do not share infrastructure, although they are linked to the same threat actor.

Advertisement. Scroll to continue reading.

The first involves loaders for the Overlord RAT and obfuscated scripts executed during npm install. While the scripts can be launched on Windows, macOS, and Linux, the payload only works on Windows systems.

The Overlord RAT provides the operator with monitoring and control capabilities, including screen capture, keylogging, window monitoring, remote shell access, file search, and a hidden desktop to perform malicious activities without detection.

As part of the second path, malicious code is executed when the package is loaded, to drop the Node.js information stealer ‘movinlike’ on the victims’ machines. The malware targets eight Discord clients, seven popular browsers, and cryptocurrency wallets for data theft.

The third path is the longest-running part of the campaign. It involves a separate downloader in each malicious version of function-flag, designed to fetch a payload from a different location.

According to Checkmarx, the infection routine is implemented so that the package installation could complete even if the payload download fails. The routine fails silently on macOS and Linux, meaning that only Windows systems are affected.

“No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target,” Checkmarx notes.

Related: Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Related Content

Malware & Threats

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.

Cybercrime

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.

Artificial Intelligence

The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.

Malware & Threats

The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

Malware & Threats

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.

Data Breaches

The attackers used a compromised BigCommerce application key held by Ribon to access customer data.

Application Security

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.

Malware & Threats

The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version