VYPR
researchPublished Oct 6, 2026· 1 source

Long-Running MALFEX Campaign on NPM Exceeds 40,000 Downloads

A persistent supply chain attack dubbed MALFEX has been active on the NPM JavaScript registry since August 2023, distributing malware like the Overlord RAT and infostealers, and has amassed over 40,000 downloads.

A sophisticated and long-running supply chain campaign, identified as MALFEX, has been actively compromising the NPM JavaScript registry since August 2023. Security researchers at Checkmarx have detailed how this campaign has stealthily distributed malicious packages, accumulating an estimated 40,000 downloads across its various components. The campaign's longevity and the types of malware it delivers underscore the persistent threats facing open-source software ecosystems.

The MALFEX campaign has deployed a total of 12 packages, with eight confirmed to be malicious. While five of these malicious packages have since been removed from the NPM registry, three remained accessible as of early October 2026: function-flag, function-color, and cdn-img-fetch. The package function-flag is particularly concerning, having been malicious since July 2025, accumulating over 37,000 downloads without any advisory flags indicating its malicious nature.

Open Source Vulnerabilities (OSV) advisories have been issued for six of the malicious packages, including tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch. However, even these advisories are not exhaustive, with the cdn-img-fetch entry only covering two of its four malicious iterations, highlighting potential gaps in detection and reporting.

Checkmarx identified three distinct delivery mechanisms employed by the threat actor behind MALFEX. While these paths do not share common infrastructure, they are attributed to the same actor. The first method involves loaders for the Overlord RAT and obfuscated scripts that execute during the npm install process. Although these scripts are designed to run on Windows, macOS, and Linux, the actual malware payload is only functional on Windows systems.

The Overlord RAT, a key component of the first delivery path, grants attackers extensive control over compromised systems. Its capabilities include screen capture, keylogging, window monitoring, remote shell access, file searching, and the ability to maintain a hidden desktop environment to conduct malicious activities undetected. This level of access poses a significant risk to user data and system integrity.

The second delivery path focuses on dropping the Node.js information stealer known as ‘movinlike’ onto victim machines. This malware is designed to exfiltrate sensitive data from eight different Discord clients, seven popular web browsers, and various cryptocurrency wallets, making it a potent tool for financial and credential theft.

The third and longest-running delivery path utilizes a separate downloader within each malicious version of the function-flag package. This downloader fetches its final payload from a different remote location, adding a layer of indirection and making attribution more challenging. The infection routine is designed to complete the package installation even if the payload download fails, and it operates silently on macOS and Linux, meaning only Windows users are directly impacted by this specific vector.

According to Checkmarx, the exposure to these malicious packages is primarily limited to systems that directly installed the named packages, as no legitimate or widely used packages depend on them. This suggests that the threat actor is likely targeting developers or systems that directly pull these specific malicious components. The campaign demonstrates a persistent and evolving threat within the open-source supply chain, requiring continuous vigilance from developers and security teams.

Synthesized by Vypr AI