Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
Checkmarx says a long-running npm campaign passed 40,000 downloads of packages dropping Overlord RAT and stealers.
Checkmarx says a threat actor has run an npm supply-chain campaign dubbed MALFEX since August 2023, publishing 12 packages, eight of them malicious. The packages accumulated more than 40,000 downloads; function-flag alone exceeds 37,000 and was still installable on October 1 without an advisory flagging it. Three paths deliver the Windows-only Overlord RAT, the Node.js stealer movinlike, or version-specific downloaders. Overlord supports screen capture, keylogging, remote shell, and file search, and exposure is limited to direct installs.
- MALFEX campaign has run since August 2023 across 12 published packages.
- function-flag exceeds 37,000 downloads and was still installable October 1.
- Three paths drop Overlord RAT, movinlike, or separate downloaders.
- Payloads run on Windows only; no popular packages depend on them.
- OSV advisories cover six packages, incompletely for cdn-img-fetch.
Full article429 words · extracted from securityweek.com · click to collapse
Malicious packages published as part of a long-running NPM supply chain campaign have accumulated over 40,000 downloads, Checkmarx reports.
Dubbed MALFEX and distributing malware such as the Overlord RAT and infostealers, the campaign has been ongoing since August 2023, when the threat actor published its first package.
To date, the threat actor has published 12 packages, eight of which are malicious. Five have been removed from the registry, but three were still installable as of October 1, namely function-flag, function-color, and cdn-img-fetch.
According to Checkmarx, function-flag deserves special attention: it has been malicious since July 2025, has more than 37,000 downloads, and no advisory flags it as malicious.
Open Source Vulnerabilities (OSV) advisories have been published for six malicious packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch. However, the entry for cdn-img-fetch covers only two of its four malicious iterations.
Checkmarx identified three independent delivery paths used in the campaign, noting that they do not share infrastructure, although they are linked to the same threat actor.
Advertisement. Scroll to continue reading.
The first involves loaders for the Overlord RAT and obfuscated scripts executed during npm install. While the scripts can be launched on Windows, macOS, and Linux, the payload only works on Windows systems.
The Overlord RAT provides the operator with monitoring and control capabilities, including screen capture, keylogging, window monitoring, remote shell access, file search, and a hidden desktop to perform malicious activities without detection.
As part of the second path, malicious code is executed when the package is loaded, to drop the Node.js information stealer ‘movinlike’ on the victims’ machines. The malware targets eight Discord clients, seven popular browsers, and cryptocurrency wallets for data theft.
The third path is the longest-running part of the campaign. It involves a separate downloader in each malicious version of function-flag, designed to fetch a payload from a different location.
According to Checkmarx, the infection routine is implemented so that the package installation could complete even if the payload download fails. The routine fails silently on macOS and Linux, meaning that only Windows systems are affected.
“No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target,” Checkmarx notes.
Related: Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining