HomeSecurityMalicious npm packages: MALFEX campaign steals data

Malicious npm packages: MALFEX campaign steals data

New malicious npm packages, distributed as part of the MALFEX campaign, have amassed a total of 40,767 downloads and were used to distribute the Overlord RAT as well as data-stealing software.

Malicious npm packages: MALFEX campaign steals data

CloudSEK and Checkmarx research links at least a dozen packages to one operator, eight of which were labeled malicious:

  • tlxbnhd
  • tldriver
  • mxdriver
  • img-to-native
  • native-runner
  • function-flag (Still live)
  • function-color (Still live)
  • cdn-img-fetch (Still live)

The Hacker News report states that the function-flag has amassed 37,419 downloads and executes code through the installation process. According to a SecurityWeek report citing Checkmarx, three packages remained available for installation as of October 1; the record is for that date and does not confirm their current status.

The case is important for development teams because installing a seemingly useful dependency can trigger code without any additional action. Such dependencies can perform actions before the developer is aware of their presence. The researchers describe three different infection routes and note that the activity spans from August 2023:

  • A loader for Overlord, an RAT written in Go that uses Solana transactions to extract the command and control (C2) address
  • A chain that installs movinlike, a Node.js data stealer that targets Discord, browsers, Telegram, and cryptocurrency wallets, and
  • Adownloader​

How malicious npm packages work

The tlxbnhd , tldriver , and mxdriver packages leverage npm lifecycle hooks to download a Windows executable. The file is presented as an image, but contains a chain that leads to Overlord , a remote access tool written in Go.

A second subset of npm packages, such as “img-to-native,” requires “cdn-img-fetch” to download and execute a Go executable, which then retrieves a malicious data stealer in Node.js capable of stealing sensitive data.

The “function-flag” package includes a post-install hook that executes a JavaScript payloadto retrieve a payload from a remote server. It has been found that each version of the package provides the payload from a different location. The “function-color” package does not include its own payload, but defines “function-flag” as a dependency.

Malicious npm packages in dependency network

See also: Axios Supply Chain Attack: Malicious versions distribute RAT

The extent of the threat from malicious npm packages

SecurityWeek, citing data from Checkmarx, reported that function-flag, function-color , and cdn-img-fetch remained installable on October 1. CloudSEK reports that function-flag was executing malicious code since July 2025 without warning for approximately fourteen months.

The number of downloads does not equal the number of infections. It does, however, indicate how widespread the packages were before they were detected. According to Checkmarx, no widely used legitimate packages depend on these names; therefore, the risk mainly concerns projects that added them directly or through another dependency. Administrators who detect malicious npm packages in their projects need to check indirect dependencies as well.

Analysts attribute the campaign to a single operator, based on common techniques and evidence linking packages to npm accounts and a GitHub repository. This attribution is the researchers’ assessment and does not substantiate geographic targeting. Checkmarx describes the distribution as broad, with no specific industry or region targeted.

Stealing data from a computer via npm

See also: VS Code Tasks: Stolen npm and Go packages download Python infostealer

Dependency control and immediate response

CloudSEK recommends excluding function-flag, cdn-img-fetch , and function-color from new installations and checking the dependencies of each project. Developers can examine lock files and installation history to see if any of the names appear directly or as an indirect dependency.

On systems where the packages are installed, security teams should check for installation scripts that download files from remote servers, as well as for unexpected AutoIt processes or executables in user profiles. CloudSEK also names a suspicious scheduled task labeled Maiden and recommends restricting outbound traffic to infrastructure related to the campaign.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Removing a package from the registry is not always enough if its dependencies remain active. CloudSEK recommends checking the entire dependency network after each removal to identify packages that continue to distribute payloads. Verifying the origin of each dependency before installation mitigates such risks.

See also: SleeperGem: Supply chain attack via RubyGems

Dependency chain protection from malicious packages

The MALFEX is a reminder that a popular package registry does not guarantee the security of every dependency. Development teams need to monitor not only updates, but also the code executed during installation, as well as the relationships between direct and indirect packages. Regular dependency checks remain critical against malicious npm packages.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS