Eight Malicious npm Packages Downloaded Over 40,000 Times in Long-Running MALFEX Malware Campaign
Researchers at CloudSEK and Checkmarx have disclosed a long-running supply chain campaign on npm, the popular repository for JavaScript code. Codenamed MALFEX, it is assessed to be the work of a single threat actor who appears to have published 12 packages since August 2023. Eight of those have been flagged as malicious, and together they were downloaded 40,767 times. The package "function-flag" accounts for 37,419 of those downloads, and its latest version was released on August 4, 2025.
The packages work in different ways. Three of them, "tlxbnhd," "tldriver," and "mxdriver," act as loaders for Overlord RAT, using install-time lifecycle hooks to download and run a Windows executable. Another group, including "img-to-native," relies on "cdn-img-fetch" to fetch and run a Go executable, which then retrieves a Node.js stealer built to harvest sensitive data. The "function-flag" package runs a postinstall hook that downloads a payload from a remote server, with each version pointing to a different location. A related package, "function-color," carries no payload itself but lists "function-flag" as a dependency.
The researchers also noted that Overlord RAT has appeared in two other campaigns since July 2026: one exploiting WordPress flaws and another targeting macOS with a fake Zoom installer. The fake Zoom campaign shares tactics with a suspected North Korea-aligned cluster called UNK_DeadDrop. This summary is based on the opening of the original report, so further detail may be available in the full article.