Cybersecurity

MALFEX Malicious Campaign on NPM Surpasses 40,000 Downloads

Checkmarx identified the MALFEX software supply chain campaign, ongoing since August 2023, which involved publishing 12 packages on NPM, eight of them malicious, with three packages remaining installable as of October 1. The campaign primarily targets Windows users with the Overlord RAT and an information stealer that extracts data from browsers, Discord, and cryptocurrency wallets.

2026-10-06
3 min read
1 views
certi.news
MALFEX Malicious Campaign on NPM Surpasses 40,000 Downloads

Malicious packages associated with the MALFEX campaign on the NPM registry have surpassed 40,000 downloads, according to Checkmarx. The campaign began in August 2023, and the threat actor has since published 12 packages, eight of which were found to be malicious.

Five packages were removed from the registry, but three were still installable on October 1: function-flag, function-color, and cdn-img-fetch. The function-flag package stands out in particular because it has remained malicious since July 2025 and recorded more than 37,000 downloads without carrying any advisory warning identifying it as a malicious package.

Three Malware Delivery Paths

Checkmarx identified three independent execution paths. They do not share the same infrastructure, but they trace back to the same threat actor. In the first path, loaders for the Overlord RAT remote access trojan are used along with obfuscated scripts that run during npm install. These scripts can run on Windows, macOS, and Linux, but the final payload operates only on Windows.

Overlord RAT gives the operator system monitoring and control capabilities, including screen capture, keystroke logging, window monitoring, remote command-line access, file searching, and the use of a hidden desktop to conduct malicious activities out of sight.

In the second path, the malicious code executes when the package is loaded to drop the movinlike information stealer onto the victim’s device. The malware targets eight Discord clients, seven common browsers, and cryptocurrency wallets to steal data.

The third path, which has persisted the longest, uses a separate downloader inside each malicious version of function-flag, fetching the payload from a different site. The infection mechanism was designed so that package installation completes even if the payload download fails, while the routine fails silently on macOS and Linux; consequently, the practical impact is concentrated on Windows systems.

What Does This Mean for Development Teams?

The Open Source Vulnerabilities initiative published alerts for six malicious packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch. However, the alert for cdn-img-fetch covers only two of the package’s four malicious versions, limiting the extent to which it can be relied upon by itself when reviewing installation records.

Checkmarx says that none of the malicious packages is a dependency of legitimate or widely used packages, so exposure is limited to systems that installed these names directly. The company also found no specific geographic or organizational targeting; anyone who installs the stealer package can become a target.

This campaign shows that a completed installation does not prove that a package is safe, particularly when the payload executes during installation or upon loading, or when the download fails silently. The most important action for affected teams is to check for these names in dependency files, NPM logs, and Windows environments, while keeping in mind that removing some packages or the appearance of an alert does not necessarily cover every malicious version.

News source
c
Author

certi.news

In the same category

You may also like

View all news