The MALFEX campaign is a long-running npm supply-chain attack that delivers Remote Access Trojans (RAT), information stealers, or open a script payload processes as payloads. The attack operates through three separate paths: a loader for Overlord RAT; a chain that installs movinlike, a a script payload stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets; and a long-running downloader hidden inside function-flag. The malware executes using npm preinstall and postinstall scripts, and code that runs when a package is loaded.
The operator signs their own work, publishing malicious packages with names like function-flag and function-color. These packages have no advisory status, making it difficult for tooling to detect them. The campaign has been linked to twelve packages, eight of which are malicious. The impact of the MALFEX campaign includes delivering malware to Windows systems through npm packages.[/subscribe_to_unlock_form]
The MALFEX campaign is a long-running npm supply-chain attack that delivers Remote Access Trojans (RAT), information stealers, or open a script payload processes as payloads. The attack operates through three separate paths: a loader for Overlord RAT; a chain that installs movinlike, a a script payload stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets; and a long-running downloader hidden inside function-flag. The malware executes using npm preinstall and postinstall scripts, and code that runs when a package is loaded.
The operator signs their own work, publishing malicious packages with names like function-flag and function-color. These packages have no advisory status, making it difficult for tooling to detect them. The campaign has been linked to twelve packages, eight of which are malicious. The impact of the MALFEX campaign includes delivering malware to Windows systems through npm packages.[emaillocker id="1283"]
The operator's activity dates back to, with the most recent malicious package being function-flag. The campaign has resulted in 40,767 recorded downloads, with three malicious packages remaining live and installable on npm as of. Blocking all eight malicious packages is recommended, along with isolating hosts, removing persistence, and rotating exposed credentials from a clean system.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1195 | Supply Chain Compromise | - |
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Discovery | E1083 | File and Directory Discovery |
| Execution | E1204 | User Execution |
| Exfiltration | E1020 | Automated Exfiltration |
| Impact | B0022 | Remote Access |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
The following reports contain further technical details:
[/emaillocker]