Threat Advisory

MALFEX Campaign Delivers Malware Through NPM Supply Chain

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The MALFEX campaign is a long-running npm supply-chain attack that delivers Remote Access Trojans (RAT), information stealers, or open a script payload processes as payloads. The attack operates through three separate paths: a loader for Overlord RAT; a chain that installs movinlike, a a script payload stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets; and a long-running downloader hidden inside function-flag. The malware executes using npm preinstall and postinstall scripts, and code that runs when a package is loaded.

The operator signs their own work, publishing malicious packages with names like function-flag and function-color. These packages have no advisory status, making it difficult for tooling to detect them. The campaign has been linked to twelve packages, eight of which are malicious. The impact of the MALFEX campaign includes delivering malware to Windows systems through npm packages.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The MALFEX campaign is a long-running npm supply-chain attack that delivers Remote Access Trojans (RAT), information stealers, or open a script payload processes as payloads. The attack operates through three separate paths: a loader for Overlord RAT; a chain that installs movinlike, a a script payload stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets; and a long-running downloader hidden inside function-flag. The malware executes using npm preinstall and postinstall scripts, and code that runs when a package is loaded.

The operator signs their own work, publishing malicious packages with names like function-flag and function-color. These packages have no advisory status, making it difficult for tooling to detect them. The campaign has been linked to twelve packages, eight of which are malicious. The impact of the MALFEX campaign includes delivering malware to Windows systems through npm packages.[emaillocker id="1283"]

The operator's activity dates back to, with the most recent malicious package being function-flag. The campaign has resulted in 40,767 recorded downloads, with three malicious packages remaining live and installable on npm as of. Blocking all eight malicious packages is recommended, along with isolating hosts, removing persistence, and rotating exposed credentials from a clean system.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195 Supply Chain Compromise -
Initial access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Persistence F0012 Registry Run Keys / Startup Folder
Discovery E1083 File and Directory Discovery
Execution E1204 User Execution
Exfiltration E1020 Automated Exfiltration
Impact B0022 Remote Access
Anti-Static Analysis B0032 Executable Code Obfuscation

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu