MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers
A persistent npm malware campaign dubbed MALFEX has been discovered, targeting Windows developers by disguising malicious executables within PNG files and employing sophisticated decryption techniques to deliver RATs and info-stealers.

A long-running npm malware campaign named MALFEX is actively targeting Windows developers, employing a multi-pronged approach to deliver remote access tools, data stealers, and hidden downloaders. Researchers have identified eight malicious npm packages published since August 2023, with download counts exceeding 40,000. The campaign utilizes a variety of obfuscation techniques, including hiding executables within PNG files or embedding encrypted programs after legitimate image data, making detection challenging.
The MALFEX campaign leverages three distinct delivery paths. The first involves packages that execute hidden scripts before or during installation. These scripts download a file labeled as an image/png, which is actually a Microsoft IExpress archive. Inside this archive, a signed AutoIt interpreter unpacks and decrypts an encrypted script using a combination of XOR, RC4, and LZNT1 compression, ultimately deploying the Overlord RAT. Researchers noted that the RAT is designed to inject itself into a signed Windows process, masquerading as a legitimate application.
The second delivery path operates differently by fetching a genuine PNG file that has an encrypted executable appended after its end marker. This encrypted data is then extracted and decrypted using AES. A subsequent Go downloader retrieves 'movinlike,' a substantial 64 MB Node.js information stealer packaged as a Windows executable. This method is particularly insidious as it executes when the package is loaded, bypassing protections that disable npm lifecycle scripts.
The Overlord RAT, delivered via the first path, offers extensive capabilities including screen capture, keystroke logging, clipboard monitoring, file searching, remote command execution, and a hidden desktop. It establishes persistence through a scheduled task that runs every five minutes with a backdated start date, making it difficult to detect through standard registry startup key checks. While the RAT can obtain command-and-control server addresses from encrypted Solana transaction memos, the analyzed samples did not exhibit active command-and-control traffic or configured Solana addresses.
The movinlike information stealer, deployed through the second path, targets sensitive developer and user data. It specifically aims to steal Discord tokens, browser cookies and saved passwords, Telegram session data, and cryptocurrency wallet credentials. The stealer modifies Discord startup scripts to gather account details and exfiltrates stolen files in compressed chunks to a Discord webhook, posing a significant threat to user accounts and financial assets.
A third, less understood delivery path involves a downloader hidden within an ASCII art package. A specific font value triggers the download, with malicious code pushed beyond the visible editor window using long strings of spaces. While the latest payload for this path was unavailable and not directly linked to movinlike, it highlights the diverse methods employed by the MALFEX operator.
Security researchers emphasize that download counts do not equate to confirmed infections, as they can include repeat installs, dependencies, and systems incapable of running the Windows payloads. However, the presence of multiple malicious packages, some lacking adequate advisories, underscores the risk to developers. Teams are urged to inspect dependency trees, lockfiles, package caches, and endpoints, and to take immediate action if affected packages are found, including host isolation, evidence preservation, and changing exposed credentials from a clean system.
The MALFEX campaign is a stark reminder of the ongoing threats within the software supply chain, particularly targeting developers who are often trusted with privileged access and sensitive information. The use of steganography to hide payloads within image files, combined with multi-stage decryption and diverse delivery mechanisms, represents a sophisticated and persistent threat that requires vigilant monitoring and robust security practices.