Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
Description
Since August 2023, a threat actor has conducted a long-running malware campaign on the NPM registry called MALFEX, publishing eight malicious packages that have accumulated over 40,000 downloads. The campaign distributes malware including the Overlord RAT and various infostealers targeting Windows systems. Some malicious packages remain installable as of October 2026, with one package, function-flag, having over 37,000 downloads and no advisory flags. The malware enables remote control, data theft from browsers, Discord clients, and cryptocurrency wallets. The infection routines are designed to fail silently on non-Windows systems, limiting impact to Windows users who directly install these packages. No geographic or organizational targeting has been observed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The MALFEX campaign involves a threat actor publishing 12 NPM packages since August 2023, eight of which are malicious. Five malicious packages have been removed, but three remain installable as of October 1, 2026, including function-flag, function-color, and cdn-img-fetch. The campaign uses three independent delivery methods: loaders for the Overlord RAT with obfuscated scripts executed during npm install (payload active on Windows only), malicious code dropping the Node.js information stealer 'movinlike' targeting Discord clients, browsers, and crypto wallets, and a downloader in function-flag fetching payloads from different locations. The infection routines allow package installation to complete even if payload download fails and fail silently on macOS and Linux. No legitimate packages depend on these malicious packages, so exposure is limited to direct installations. No geographic or organizational targeting has been identified.
Potential Impact
The campaign enables attackers to remotely monitor and control infected Windows systems via the Overlord RAT, including screen capture, keylogging, remote shell access, and stealthy desktop control. The information stealer targets multiple Discord clients, popular browsers, and cryptocurrency wallets, potentially leading to credential and asset theft. The malware affects only Windows systems where the malicious packages are directly installed. The campaign has resulted in over 40,000 downloads of malicious packages, with one package alone having over 37,000 downloads without being flagged by advisories. The silent failure on non-Windows systems limits impact to Windows users.
Defensive Guidance
Five of the eight malicious packages have been removed from the NPM registry, but three remain installable as of October 1, 2026. Users should avoid installing the packages function-flag, function-color, and cdn-img-fetch. Since no legitimate packages depend on these malicious packages, exposure is limited to direct installations. Users and organizations should audit their dependencies to ensure these packages are not present. Monitor vendor advisories such as Open Source Vulnerabilities (OSV) for updates on affected packages. Patch status is not applicable as this is a malware campaign involving malicious packages rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.73,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/long-running-npm-malware-campaign-accumulates-40000-downloads/","fetched":true,"fetchedAt":"2026-10-06T10:48:20.883Z","wordCount":1072}
Threat ID: 6ac4d1f52cdf04f6569c34ba
Added to database: 10/06/2026, 10:48:21 UTC
Last enriched: 10/06/2026, 10:48:27 UTC
Last updated: 10/06/2026, 12:48:24 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.