A Long-Running NPM Malware Campaign Has Accumulated Over 40,000 Downloads
A malicious campaign targeting the Node Package Manager (NPM) supply chain has been secretly accumulating downloads for over a year. Dubbed MALFEX, the threat actor behind this campaign has published no fewer than 12 packages, eight of which are malicious and have resulted in more than 40,000 downloads.
The campaign began in August 2023, with the first package being published by the threat actor. Since then, they have been consistently publishing new packages, many of which have gone unnoticed by the wider security community. However, researchers at Checkmarx have been tracking the activity and have identified several key aspects of the campaign.
One of the most concerning aspects of MALFEX is its use of multiple delivery paths to infect victims’ machines. According to Checkmarx, there are three independent paths used in the campaign, which do not share infrastructure but are linked to the same threat actor. The first path involves loaders for the Overlord RAT and obfuscated scripts executed during npm install. These scripts can be launched on Windows, macOS, and Linux systems, but the payload only works on Windows.
The second path executes malicious code when the package is loaded, dropping a Node.js information stealer known as ‘movinlike’ onto the victims’ machines. This malware targets eight Discord clients, seven popular browsers, and cryptocurrency wallets for data theft.
The third and longest-running part of the campaign involves a separate downloader in each malicious version of function-flag, designed to fetch a payload from a different location. Notably, this routine fails silently on macOS and Linux systems, meaning that only Windows users are affected by this particular path.
Checkmarx notes that exposure is limited to systems that installed these package names directly, with no geographic or organizational targeting in sight. However, the fact remains that over 40,000 downloads have been accumulated through this campaign, making it a significant threat to security-conscious individuals and organizations alike.
The Overlord RAT provides the operator with monitoring and control capabilities, including screen capture, keylogging, window monitoring, remote shell access, file search, and a hidden desktop to perform malicious activities without detection. This malware is particularly concerning due to its ability to evade detection and the sensitive data it can steal from compromised machines.
To mitigate this risk, users are advised to regularly review their package dependencies and ensure that they are not installing malicious packages. Developers should also prioritize security best practices when publishing packages to NPM, including implementing proper validation and testing procedures.
Ultimately, the MALFEX campaign serves as a reminder of the importance of vigilance in the face of evolving cybersecurity threats. By staying informed and taking proactive steps to secure our systems, we can reduce the risk of falling victim to such attacks and protect our sensitive data from being compromised.
Source: SecurityWeek — 2026-10-06