MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers
MALFEX npm packages hide Windows malware in fake PNG files, delivering Overlord RAT and the movinlike stealer.
Checkmarx reported MALFEX, an npm campaign active since August 2023 that targets Windows developers through eight malicious packages with 40,767 downloads by October 1, 2026. One path fetches a file labeled as a PNG that is actually a Microsoft IExpress archive, then uses a signed AutoIt interpreter to launch Overlord RAT, which can log keystrokes, capture screens, and persist with a five-minute scheduled task. A second chain appends encrypted data to a real PNG, decrypts it with AES, and uses a Go downloader to retrieve movinlike, a Node.js stealer that sends Discord, browser, Telegram, and wallet data to a Discord webhook. Three malicious packages were still installable in the researchers' October 1 snapshot.
- Eight malicious npm packages recorded 40,767 downloads since August 2023.
- A fake PNG download delivers Overlord RAT through a signed AutoIt loader.
- Another chain hides encrypted data after a real PNG and fetches movinlike.
- Overlord persists with a scheduled task that runs every five minutes.
- movinlike steals Discord, browser, Telegram, and cryptocurrency wallet data.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cdn.discordapp.com | ag@4.0.0 payload hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… function-fla |
| domain | index.js | r list, and researchers saw no command-and-control traffic. index[.]js (Source – Checkmarx) This is a supported capability, not |
| domain | postinstall.js | hive, a signed AutoIt interpreter runs an encrypted script. postinstall[.]js (Source – Checkmarx) Several decoding steps, including XO |
| ipv4 | 104.234.65.75 | w/proj/main/banner.jpg cdn-img-fetch@1.0.3 payload hxxp[:]//104.234.65.75:700/setup.exe movinlike download hxxp[:]//104.234.65.75/set |
| ipv4 | 191.96.81.101 | 7598386237/malfex.exe function-flag@2.3.8 payload hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex. |
| ipv4 | 45.89.30.194 | flag@3.0.0 ; incomplete in the source’s IoC table hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.e |
| ipv4 |
Full article1,245 words · extracted from cybersecuritynews.com · click to collapse
A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders.
The attack uses eight malicious packages and three separate delivery paths, including a Windows executable disguised as a PNG and an encrypted program hidden after real image data.
The operator has published packages since August 2023. Across the eight malicious packages, npm recorded 40,767 downloads by October 1, 2026, including 3,017 during the previous week.
Those numbers show package reach, not confirmed infections: downloads can include repeat installs, dependencies, and systems that cannot run the Windows payloads.
Checkmarx researchers identified the campaign in an October 5 report. They linked twelve packages to what appears to be one operator, with four clean packages used as cover.
The MALFEX name appeared in publisher accounts, repository records, and package documentation, while the image decryption key also carried the same branding.
MALFEX npm Malware Hides Executables in PNG Files
The first delivery path uses three packages that run hidden scripts before or after installation. These scripts fetch a file served as image/png, save it as a Windows executable, and launch it.
Despite its image label, the download is a Microsoft IExpress archive rather than a normal PNG. Inside the archive, a signed AutoIt interpreter runs an encrypted script.
![postinstall[.]js (Source - Checkmarx)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVB7sX-3j9ukihIFPJm0iqdLtflSFv8SiMJk159pnk6SHoEKSMMp9Q1oAju_CR59OFmQQ1crNdVqJTvP3R2rwlEQfYzD3TiX2F22Y8SBrBNr2nXVz8IEbkICsqMEjyZJes9Ai6FSzVlP3SmLCXImM-WsORcJcY48fpEZlGj7dysJIjoyGSiCDsTuS2boY/s1600/index%5B.%5Djs%20(Source%20-%20Checkmarx).webp)
Several decoding steps, including XOR, RC4, and LZNT1 compression, reveal Overlord RAT. Code analysis showed instructions to inject the RAT into a signed Windows process while making Explorer appear to be its parent. Researchers did not observe that injection during runtime testing.
The second path works differently. A chain of three packages fetches a genuine PNG with encrypted executable data added after its end marker.
The malware extracts that data and decrypts it using AES. A Go downloader then retrieves movinlike, a 64 MB Node.js information stealer packaged as a Windows executable.
This chain runs when the package is loaded, not through an install script. That distinction matters because disabling npm lifecycle scripts does not stop it.
Cyber Security News previously covered another npm attack hiding a RAT in PNG images, although that campaign stored payloads in image pixels rather than using MALFEX’s methods.
Overlord supports screen capture, keystroke logging, clipboard collection, file searches, remote commands, and a hidden desktop.
Its loader creates a scheduled task that runs every five minutes and carries a backdated 2020 start date. Checking only registry startup keys would miss this persistence method.
The RAT can obtain server addresses from encrypted Solana transaction memos. However, the analyzed sample had no configured Solana address or server list, and researchers saw no command-and-control traffic.
![index[.]js (Source - Checkmarx)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2oRH18PQ4Rr_QlwWmmA8A_EPoPnrfQi5siIlvYmIIq9Y4E6ShDt_9RysB58Q_sX1_j_ASKkjdRdh9r-IOOIdy1zbI1IubJllaGuNOfMt3umnxwff9oByZftsnEHq5LTpQrURnx4GDohSDkC17HqBoYGaBHGCbdKYJCtCZ_VgbG3VZcPKQjrEFKsijPtU/s1600/postinstall%5B.%5Djs%20(Source%20-%20Checkmarx).webp)
This is a supported capability, not proof that blockchain-based control was active in the tested infection. The movinlike stealer targets Discord tokens, browser cookies and saved passwords, Telegram sessions, and cryptocurrency wallets.
It changes Discord startup scripts, gathers account details, and sends stolen files to a Discord webhook in compressed chunks. Earlier reporting on StegaBin’s multistage credential theft shows why developer package installs deserve close security checks.
The third path hides a downloader inside an ASCII art package. A specific font value triggers the download, while long runs of spaces push malicious code beyond the visible editor window.
Download errors are silently ignored. Its latest analyzed payload was unavailable, and Checkmarx found no evidence connecting this separate downloader to movinlike.
Three malicious packages remained installable in Checkmarx’s October 1 snapshot. Two lacked malware advisories, while another advisory covered only two of four malicious versions.
Teams relying only on advisory feeds could therefore miss known bad code. These findings describe the report’s dated checks, not a fresh registry status check.
Developers should inspect dependency trees, lockfiles, package caches, and Windows endpoints. If an affected package was installed, isolate the host, preserve evidence, remove persistence, and change exposed passwords from a clean system.
End Telegram sessions and move exposed cryptocurrency funds to new wallets. Block all eight malicious packages and their specific download paths without blocking shared hosting services wholesale.
Removing packages alone does not undo stolen sessions or installed malware. Related coverage of fake npm install messages and compromised SAP npm packages reinforces the risk of trusting package setup activity.
Unit 42’s npm threat landscape analysis provides wider context for these supply-chain risks. Security teams should also review account activity and remove malicious copies from internal registries before developers reinstall affected dependencies.
Indicators of compromise (IoCs):-
| Package | Malicious versions |
|---|---|
function-flag | 1.7.3, 4.0.0, 3.0.0, 2.3.5–2.3.9 |
function-color | 1.7.3, 1.0.0 |
cdn-img-fetch | 1.0.0–1.0.3 |
img-to-native | 1.0.0–1.0.3 |
native-runner | 1.0.0–1.0.3 |
tlxbnhd | 0.0.1 |
tldriver | 0.0.1 |
mxdriver | 0.0.1, 0.0.2 |
These version ranges are explicitly identified as malicious; Checkmarx states that function-flag@2.3.4 is not malicious.
URLs and Hosts
| Source-listed indicator | Role |
|---|---|
hxxps[:]//api.imghippo.com/files/hOG8244hc.png | Overlord loader served as PNG |
www.image.com | Second Overlord delivery domain associated with mxdriver |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png | Stealer-chain image; used by cdn-img-fetch versions 1.0.0–1.0.2 |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.jpg | cdn-img-fetch@1.0.3 payload |
hxxp[:]//104.234.65.75:700/setup.exe | movinlike download |
hxxp[:]//104.234.65.75/setup.exe | Alternate movinlike download path |
hxxps[:]//cdnzona.discloud.app/node.exe | function-flag@1.7.3 payload |
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe | function-flag@4.0.0 payload |
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… | function-flag@3.0.0; incomplete in the source’s IoC table |
hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe | function-flag@2.3.9 payload |
hxxps[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe | function-flag@2.3.8 payload |
hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe | function-flag@2.3.7 payload |
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe | function-flag@2.3.6 payload |
hxxps[:]//51.137.158.178/download | function-flag@2.3.5 payload |
discord.com/api/webhooks/1553545982975811594/… | movinlike data-theft webhook; token omitted by the source |
Checkmarx’s payload-version table uses hxxp[:] rather than hxxps[:] for the two 45.89.30.194 paths, the 191.96.81.101 path, and 51.137.158.178/download. Both protocol variants are therefore source-listed. The report also warns against blocking shared service domains wholesale; use the specific malicious paths.
SHA-256 Hashes
| Artifact | SHA-256 |
|---|---|
| Overlord RAT loader served as PNG | 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793 |
Signed AutoIt3.exe from archive | 5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7 |
Encrypted Oxygen.a3x / h.a3x script | fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67 |
| Decoded Overlord RAT | 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210 |
Current banner.png | 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106 |
| Stealer-chain downloader, September 25 | 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849 |
| Stealer-chain downloader, September 25 | e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4 |
| Stealer-chain downloader, September 25 | ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807 |
| Stealer-chain downloader, September 26 | 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b |
tlxbnhd/scripts/postinstall.js | 7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e |
| movinlike | c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437 |
img-to-native@1.0.1/index.js | c7cf2323e4923428984297db7715d75fec5b964fe65c325b53e3fa360f3b8d86 |
cdn-img-fetch@1.0.0/index.js and version 1.0.1 | 430300450f5acbd69c29f02d8c2e243f7d1d6202d1826f6e4d7715f95c47299b |
cdn-img-fetch@1.0.2/index.js | 4cba0c785e66d517eabd0164f34a9c2d04549da93b5ee3eebdce5558daa2f47c |
cdn-img-fetch@1.0.3/index.js | 5c933aa533721fa293b284170dd4611a4d88f88cc89f2d9c28ea4e22305b1f75 |
cdn-img-fetch@1.0.3 — banner.jpg | 8f7ed69fb5505b57f06e673826779d459f7735739756de73a6d3347a9c8ea0cc |
function-flag@1.7.3/index.js | d54853d6be467567d9f22d7f22ac48214df52c1f9c7a503930e901286423044a |
function-flag@1.7.3/example.js | 886b84f83a0f760e664046ba40d8c800b7d0cf72190e13ca031ee5cf50f45bee |
All hashes are reproduced as published. Checkmarx notes that movinlike can be rebuilt easily, so defenders should pair hash checks with file, task, and network evidence. The signed AutoIt interpreter is legitimate software; its hash alone does not establish infection outside this campaign context.
Host Artifacts and Persistence
| Indicator | Meaning |
|---|---|
%LOCALAPPDATA%\ScopeSmart Technologies Inc\ | Overlord loader directory |
%LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe | Interpreter used by the loader |
%LOCALAPPDATA%\ScopeSmart Technologies Inc\h.a3x | Encrypted AutoIt script |
%LOCALAPPDATA%\ScopeSmart Technologies Inc\SmartScope.vbs | Associated script |
Scheduled task \Maiden | Overlord persistence |
Task command "AutoIt3.exe" "h.a3x" | Scheduled execution |
| Task interval: every five minutes, no end time | Persistence timing |
Task start date: 1/1/2020 | Backdated task metadata |
Task author: Welcome; comment: Wichita | Associated task metadata |
<package dir>\gldriver_pre_core.exe | Dropped Overlord payload, deleted after launch |
<package dir>\gldriver_pre_asset.exe | Dropped Overlord payload, deleted after launch |
%APPDATA%\Microsoft\Windows\node_runtime_helper.exe | Decrypted stealer-chain downloader |
%TEMP%\._cif_data | Stealer-chain intermediate file |
%APPDATA%\node.exe | function-flag@1.7.3 payload |
These paths and task details are documented in the source’s host-artifact and persistence sections.
Supporting Attribution Indicators
| Indicator | Source context |
|---|---|
malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4 | npm publisher accounts |
corpmalfex[@]gmail.com | Payload repository Git author email |
malfexteam2027 | Stealer-chain AES decryption key |
Murizada | Owner name credited in the package README |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.