MalwareMedium

Long-running MALFEX npm campaign spreads RAT and stealer, reaches 40,000 downloads

Checkmarx says a single actor has used npm packages since August 2023 to deliver Overlord RAT and a Node.js stealer; three packages were still live on October 1.

Long-running MALFEX npm campaign spreads RAT and stealer, reaches 40,000 downloads

At a glance

  • Checkmarx tracked 12 npm packages from one actor, eight of them malicious, with more than 40,000 combined downloads, SecurityWeek reported.
  • function-flag alone has over 37,000 downloads and turned malicious in July 2025.
  • Payloads include Overlord RAT on Windows and a stealer targeting Discord clients, browsers and crypto wallets.
  • function-flag, function-color and cdn-img-fetch were still installable as of October 1.

A threat actor has been distributing malware through the npm registry since August 2023 in a campaign that has accumulated more than 40,000 downloads, SecurityWeek reported on October 6, citing research from Checkmarx. The campaign, dubbed MALFEX, delivers a remote access trojan and an information stealer, and some of its packages were still available for installation at the start of October.

What happened

According to SecurityWeek, Checkmarx linked 12 npm packages to the same operator, eight of which were malicious. Five packages have been removed from the registry, but three, function-flag, function-color and cdn-img-fetch, were still installable as of October 1.

The most widely downloaded package, function-flag, has more than 37,000 downloads on its own. It became malicious in July 2025 and, according to the report, was not covered by a malicious-package advisory. Open Source Vulnerabilities (OSV) advisories exist for tlxbnhd, tldriver, mxdriver, img-to-native, native-runner and cdn-img-fetch, though the cdn-img-fetch entry documents only two of its four malicious versions, SecurityWeek said.

Technical details

Checkmarx identified three independent delivery paths with no shared infrastructure, according to the report. In the first, loaders run during npm install on Windows, macOS and Linux but deploy Overlord RAT only on Windows. Overlord supports screen capture, keylogging, window monitoring, remote shell access, file search and a hidden desktop.

The second path executes when a package is loaded and drops a Node.js information stealer, called movinlike, that targets eight Discord clients, seven popular browsers and cryptocurrency wallets. The third and longest-running path, used by function-flag, relies on a different downloader in each malicious version to fetch payloads from changing locations; its failure routines only affect Windows systems.

Who is affected

Checkmarx said no legitimate or widely used packages depend on any of the operator's packages, so exposure is limited to systems that installed these package names directly. The researchers did not identify any geographic or organizational targeting, SecurityWeek reported.

What to do

Developers and security teams should search lockfiles, build caches and developer workstations for the package names listed above and remove them. Any Windows machine that installed or loaded one of these packages should be treated as compromised: investigate for RAT activity, rotate credentials, browser sessions, Discord tokens and wallet keys stored on the system. Teams can limit similar risks by pinning dependencies, reviewing new or rarely used packages before adoption and disabling install scripts in CI where possible.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.