Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

A Long-Running NPM Malware Campaign Has Infected Over 40,000 Systems

A sophisticated malware campaign has been quietly targeting developers and users of Node.js packages on the npm registry for nearly three years. Dubbed MALFEX by security researchers at Checkmarx, the operation has accumulated over 40,000 downloads since its inception in August 2023. The malicious packages have been designed to install a range of malware, including the notorious Overlord RAT and infostealers.

The campaign’s primary objective is to compromise systems running Node.js, with the attackers utilizing three distinct delivery paths to achieve their goal. One path involves loading scripts during the npm installation process that can execute on Windows, macOS, and Linux operating systems. However, the payload only activates on Windows-based machines, allowing the Overlord RAT to gain control over infected systems.

The Overlord RAT grants the attacker a range of malicious capabilities, including screen capture, keylogging, window monitoring, remote shell access, file search, and the ability to create a hidden desktop for covert activities. In addition, the attackers have designed a secondary path that executes malicious code when the package is loaded, dropping the Node.js information stealer ‘movinlike’ on the victim’s machine.

This malware targets eight Discord clients, seven popular browsers, and cryptocurrency wallets for data theft, making it a significant threat to users who rely on these applications. The third delivery path involves a separate downloader in each malicious version of function-flag, designed to fetch a payload from a different location. This approach ensures that the infection routine can complete even if the payload download fails, with the malware failing silently on macOS and Linux systems.

The npm registry has been criticized for its lack of robust security measures, allowing malicious packages to be published and downloaded by unsuspecting users. Checkmarx notes that legitimate or widely used packages do not depend on operator packages, limiting exposure to systems that installed these package names directly.

In practical terms, this campaign highlights the importance of vigilance when managing dependencies in Node.js projects. Users are advised to regularly review their package list, ensuring they only install trusted and verified modules. Furthermore, developers should prioritize the adoption of robust security practices, such as using secure coding guidelines and implementing regular code reviews. By taking these precautions, users can significantly reduce the risk of falling victim to this or similar campaigns in the future.


Source: SecurityWeek — 2026-10-06