Skip to main content

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

0
High
Published: 10/06/2026 (10/06/2026, 10:34:25 UTC)
Source: SecurityWeek

Description

Since August 2023, a threat actor has conducted a long-running malware campaign on the NPM registry called MALFEX, publishing eight malicious packages that have accumulated over 40,000 downloads. The campaign distributes malware including the Overlord RAT and various infostealers targeting Windows systems. Some malicious packages remain installable as of October 2026, with one package, function-flag, having over 37,000 downloads and no advisory flags. The malware enables remote control, data theft from browsers, Discord clients, and cryptocurrency wallets. The infection routines are designed to fail silently on non-Windows systems, limiting impact to Windows users who directly install these packages. No geographic or organizational targeting has been observed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/06/2026, 10:48:27 UTC

Technical Analysis

The MALFEX campaign involves a threat actor publishing 12 NPM packages since August 2023, eight of which are malicious. Five malicious packages have been removed, but three remain installable as of October 1, 2026, including function-flag, function-color, and cdn-img-fetch. The campaign uses three independent delivery methods: loaders for the Overlord RAT with obfuscated scripts executed during npm install (payload active on Windows only), malicious code dropping the Node.js information stealer 'movinlike' targeting Discord clients, browsers, and crypto wallets, and a downloader in function-flag fetching payloads from different locations. The infection routines allow package installation to complete even if payload download fails and fail silently on macOS and Linux. No legitimate packages depend on these malicious packages, so exposure is limited to direct installations. No geographic or organizational targeting has been identified.

Potential Impact

The campaign enables attackers to remotely monitor and control infected Windows systems via the Overlord RAT, including screen capture, keylogging, remote shell access, and stealthy desktop control. The information stealer targets multiple Discord clients, popular browsers, and cryptocurrency wallets, potentially leading to credential and asset theft. The malware affects only Windows systems where the malicious packages are directly installed. The campaign has resulted in over 40,000 downloads of malicious packages, with one package alone having over 37,000 downloads without being flagged by advisories. The silent failure on non-Windows systems limits impact to Windows users.

Defensive Guidance

Five of the eight malicious packages have been removed from the NPM registry, but three remain installable as of October 1, 2026. Users should avoid installing the packages function-flag, function-color, and cdn-img-fetch. Since no legitimate packages depend on these malicious packages, exposure is limited to direct installations. Users and organizations should audit their dependencies to ensure these packages are not present. Monitor vendor advisories such as Open Source Vulnerabilities (OSV) for updates on affected packages. Patch status is not applicable as this is a malware campaign involving malicious packages rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.73,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/long-running-npm-malware-campaign-accumulates-40000-downloads/","fetched":true,"fetchedAt":"2026-10-06T10:48:20.883Z","wordCount":1072}

Threat ID: 6ac4d1f52cdf04f6569c34ba

Added to database: 10/06/2026, 10:48:21 UTC

Last enriched: 10/06/2026, 10:48:27 UTC

Last updated: 10/06/2026, 12:48:24 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses