The MALFEX npm supply-chain malware campaign has quietly amassed more than 40,000 downloads across eight malicious packages since August 2023, with several still available in the official registry despite active abuse reports.[1][2][3]
Researchers at CloudSEK and Checkmarx attribute the activity to what appears to be a single adversary using Portuguese-language npm accounts and a linked GitHub repository, publishing at least 12 packages between August 2023 and September 2026, eight of which have been classified as malicious.[3][13][15] Checkmarx reports a total of 40,767 downloads across the malware-laden packages as of October 1, 2026, with 3,017 downloads occurring in the preceding week, highlighting that the campaign remains active rather than historical.[3] The package function-flag alone has been malicious since July 2025 and accounts for 37,419 downloads, yet no official advisory currently flags it as unsafe on npm.[1][2][3]
According to the published research, MALFEX abuses npm’s postinstall scripts to deploy Windows malware including the Overlord remote access trojan (RAT) and an infostealer dubbed “movinlike,” giving the operator persistent remote control, screen capture, keylogging, and credential theft capabilities on compromised hosts.[3][4][13] CloudSEK notes that stolen data includes browser credentials and Discord access tokens, which can be monetized or leveraged for further account takeover and lateral movement.[13][15] Checkmarx describes three distinct delivery paths that do not share infrastructure but are linked by overlapping code and behavior, reinforcing the assessment that a single actor is iterating on the campaign over time.[3][4]
The threat actor has cycled packages through the registry, with some being removed after detection while others remain live under innocuous-sounding names that can be pulled into projects as transient or indirect dependencies.[1][2][3] SecurityWeek and other trackers note that, as of early October, three malicious packages—including function-flag, function-color, and cdn-img-fetch—were still installable from npm, providing an ongoing foothold into developer environments and CI/CD pipelines.[1][2][4] Because the malicious logic is executed at install time via scripts, developers may never directly import the compromised code in application source files, making the infection easy to miss during routine reviews.[3][13]
For defenders, MALFEX underscores the limitations of relying solely on CVE-driven scanning and ecosystem advisories to manage software supply-chain risk, particularly when malicious packages can operate for months without formal flags.[1][2][12] Neither CloudSEK nor Checkmarx cite any CVE assignments for the campaign, and researchers explicitly call out the absence of an advisory for function-flag despite more than a year of malicious behavior and tens of thousands of downloads.[1][3][13] This gap means security teams must treat npm dependency hygiene as a first-class control, continuously reviewing third-party packages and their install-time scripts rather than assuming that unflagged packages are benign.[3][12]
Organizations that rely on npm should immediately audit dependency trees for the known MALFEX-linked packages, block them in private registries and build systems, and hunt for indicators of Overlord RAT and the “movinlike” infostealer on Windows endpoints where those packages may have been installed.[3][4][13] Pulling indicators of compromise, command-and-control domains, and payload hashes from the published research, and feeding them into endpoint detection and response tools and network monitoring, can help identify covert infections and cut off active sessions.[3][12][13] Longer term, teams are advised to pin dependencies, use lockfiles, and prefer vetted internal mirrors or registries to reduce exposure to malicious uploads, while closely following independent threat research coverage of ecosystems like npm that continue to be attractive targets for supply-chain attackers.[3][4][13]
References
- Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
- MALFEX: 8 вредоносных пакетов в NPM, 40 000 загрузок, три доступны
- MALFEX npm Malware Campaign: Three Payloads And An …
- Malware & Threats – HazeTec
- www.cloudsek.com › case-studiesCase Studies – cloudsek.com
- MALFEX – A malicious npm postinstall no advisory has caught for fourteen months | CloudSEK
- Ameaça no npm espalha vírus no Windows e rouba dados do Discord
