MALFEX npm malware campaign tops 40,000 downloads

MALFEX npm malware campaign tops 40,000 downloads

A supply chain campaign targeting the npm registry has been running for more than three years, and its malicious packages have been downloaded more than 40,000 times, according to Checkmarx.

The researchers call the campaign MALFEX. It has delivered the Overlord remote access trojan (RAT) and information-stealing malware. The threat actor published its first package in August 2023.

Three malicious packages still available

The operator has published 12 packages to npm, the main package registry for JavaScript and Node.js developers. Eight of them are malicious. Five of these have been taken down. As of October 1, three could still be installed: function-flag, function-color and cdn-img-fetch.

Checkmarx highlighted function-flag in particular. The package has been malicious since July 2025 and has been downloaded more than 37,000 times. No advisory currently flags it as malicious.

Other parts of the campaign have been documented. Open Source Vulnerabilities (OSV), a public database of security advisories for open source packages, lists entries for six of the malicious packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner and cdn-img-fetch. Even so, the cdn-img-fetch entry covers only two of the four malicious versions of that package.

Three separate delivery paths

Checkmarx found three independent ways the campaign delivers malware. They do not share infrastructure, but the researchers link all three to the same threat actor.

Overlord RAT loaders. The first path uses obfuscated scripts that run during npm install, along with loaders for the Overlord RAT. The scripts can start on Windows, macOS and Linux, but the payload only works on Windows.

Once installed, Overlord gives the operator wide monitoring and control over the infected machine. Its features include:

  • screen capture
  • keylogging
  • window monitoring
  • remote shell access
  • file search
  • a hidden desktop, which lets the attacker work on the system without being noticed

The movinlike stealer. In the second path, malicious code runs when the package is loaded and drops a Node.js infostealer called "movinlike". The malware steals data from eight Discord clients, seven popular browsers and cryptocurrency wallets.

function-flag downloaders. The third path has been active the longest. Each malicious version of function-flag contains its own downloader, and each one fetches its payload from a different location.

Checkmarx noted that the infection routine is written so that the package still installs even if the payload download fails. On macOS and Linux, the routine fails silently, which means only Windows systems are affected.

Who is exposed

The packages are not deeply embedded in the wider ecosystem. According to Checkmarx, only systems that installed the malicious packages by name are exposed, because none of them is a dependency of a legitimate package.

"No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target," Checkmarx said.

That limits how far the infection can spread. It does not make the download numbers less concerning, especially for function-flag, which has stayed live and unflagged for months.

The Bigger Picture

The most notable part of MALFEX is how long it has lasted. It has been running since August 2023, and a package with more than 37,000 downloads is still listed with no advisory. Removing packages and publishing advisories has clearly not kept pace with the operator. The partial OSV entry for cdn-img-fetch points to the same gap. Teams that rely on advisory feeds alone may conclude they are safe when they are not.

Silent failures, payloads hosted in different places and the decision to target only Windows all make the campaign harder to spot. These traits match a wider trend of cross-platform malware campaigns built to evade detection rather than spread quickly. The broader risk to software repositories has also come up recently in the OpenInfra Europe Artifactory breach.

Developers should check their projects and build systems for the package names listed above. Any affected Windows machine should be treated as compromised, and credentials, browser data and wallets stored on it should be considered stolen. It is also worth watching how quickly npm removes the three remaining packages, and whether advisories for function-flag and function-color follow.