Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Context for Trump’s ‘Take Out’ Los Angeles, San Diego Remarks

    October 7, 2026

    US stock market hits all-time high as investors bet big on AI | Financial Markets News

    October 7, 2026

    Ex-Ramp engineers raise $20M for platform Melius after scrapping their first product

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Context for Trump’s ‘Take Out’ Los Angeles, San Diego Remarks
    • US stock market hits all-time high as investors bet big on AI | Financial Markets News
    • Ex-Ramp engineers raise $20M for platform Melius after scrapping their first product
    • 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
    • Bitcoin.de Seeks New Model After BaFin Rejects MiCA Bid
    • NASA Glenn Invites Phase 1 Proposals for Aerospace Power Systems Laboratory
    • Prysmian extends 30-year copper partnership with new supply agreement
    • Pedro Sánchez is a master of the political comeback. But calling a snap election in Spain may be a gamble too far | Paolo Gerbaudo
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Malicious packages published as part of a long-running NPM supply chain campaign have accumulated over 40,000 downloads, Checkmarx reports.

    Dubbed MALFEX and distributing malware such as the Overlord RAT and infostealers, the campaign has been ongoing since August 2023, when the threat actor published its first package.

    To date, the threat actor has published 12 packages, eight of which are malicious. Five have been removed from the registry, but three were still installable as of October 1, namely function-flag, function-color, and cdn-img-fetch.

    According to Checkmarx, function-flag deserves special attention: it has been malicious since July 2025, has more than 37,000 downloads, and no advisory flags it as malicious.

    Open Source Vulnerabilities (OSV) advisories have been published for six malicious packages: tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, and cdn-img-fetch. However, the entry for cdn-img-fetch covers only two of its four malicious iterations.

    Checkmarx identified three independent delivery paths used in the campaign, noting that they do not share infrastructure, although they are linked to the same threat actor.

    Advertisement. Scroll to continue reading.

    The first involves loaders for the Overlord RAT and obfuscated scripts executed during npm install. While the scripts can be launched on Windows, macOS, and Linux, the payload only works on Windows systems.

    The Overlord RAT provides the operator with monitoring and control capabilities, including screen capture, keylogging, window monitoring, remote shell access, file search, and a hidden desktop to perform malicious activities without detection.

    As part of the second path, malicious code is executed when the package is loaded, to drop the Node.js information stealer ‘movinlike’ on the victims’ machines. The malware targets eight Discord clients, seven popular browsers, and cryptocurrency wallets for data theft.

    The third path is the longest-running part of the campaign. It involves a separate downloader in each malicious version of function-flag, designed to fetch a payload from a different location.

    According to Checkmarx, the infection routine is implemented so that the package installation could complete even if the payload download fails. The routine fails silently on macOS and Linux, meaning that only Windows systems are affected.

    “No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target,” Checkmarx notes.

    Related: Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    Related: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Accumulates campaign Downloads LongRunning Malware npm
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

    AI accelerates n-day attacks, as flaw disclosures and exploits double

    Ninja Forms plugin flaw exploited to hack WordPress sites

    What exactly is ISOC? And what does it mean for you?

    The AI app builder your team trusts has a root-level backdoor

    Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Context for Trump’s ‘Take Out’ Los Angeles, San Diego Remarks

    October 7, 2026

    US stock market hits all-time high as investors bet big on AI | Financial Markets News

    October 7, 2026

    Ex-Ramp engineers raise $20M for platform Melius after scrapping their first product

    October 7, 2026

    8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

    October 7, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Context for Trump’s ‘Take Out’ Los Angeles, San Diego Remarks

    October 7, 2026

    US stock market hits all-time high as investors bet big on AI | Financial Markets News

    October 7, 2026

    Ex-Ramp engineers raise $20M for platform Melius after scrapping their first product

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.