MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers
MALFEX npm packages hide Windows malware in fake PNG files, delivering Overlord RAT and the movinlike stealer.
Checkmarx reported MALFEX, an npm campaign active since August 2023 that targets Windows developers through eight malicious packages with 40,767 downloads by October 1, 2026. One path fetches a file labeled as a PNG that is actually a Microsoft IExpress archive, then uses a signed AutoIt interpreter to launch Overlord RAT, which can log keystrokes, capture screens, and persist with a five-minute scheduled task. A second chain appends encrypted data to a real PNG, decrypts it with AES, and uses a Go downloader to retrieve movinlike, a Node.js stealer that sends Discord, browser, Telegram, and wallet data to a Discord webhook. Three malicious packages were still installable in the researchers' October 1 snapshot.