Windows developers who rely on npm packages are currently facing a sophisticated supply chain threat involving a campaign named MALFEX. Disguised as harmless image files, this malware delivers remote access tools, credential stealers, and covert downloaders through specially crafted npm packages. Security researchers uncovered that these attacks have been ongoing since August 2023 and have already racked up tens of thousands of downloads.
How MALFEX Operates: Hidden Executables, Stealthy Payloads
MALFEX operates through three primary attack vectors. In the first, certain malicious packages embed scripts that download what appears to be a PNG file but which is actually an executable packed in a Microsoft IExpress archive. When deployed, this archive launches an AutoIt interpreter to decrypt and run a RAT—called Overlord—using multiple layers of obfuscation including XOR, RC4, and LZNT1 compression.
The second delivery path makes the deception subtler. It pulls in legitimate image files (PNGs), but appends encrypted executable data after the image’s end marker. A Go-based downloader extracts, decrypts, and caches this data, then executes a stealer component dubbed movinlike. That tool harvests browser credentials, Discord tokens, Telegram sessions, cookies, and crypto wallet data, and sends it back to attackers through Discord webhooks. Crucially, this vector activates when the malicious module is required—not just during installation—rendering npm lifecycle script defenses ineffective.
The third route hides its downloader in an ASCII-art-based package. A crafty trick using font value manipulation and long runs of spaces pushes the malicious payload out of sight in editors. This path is less understood; the final malware in this chain was not retrievable during testing, and no clear link to movinlike has yet been established.
Scope, Persistence & Indicators
MALFEX has released eight confirmed malicious packages under multiple version numbers—some clean versions exist to camouflage the campaign. From launch until October 1, 2026, these packages amassed over 40,700 downloads; just over 3,000 of those occurred in the week before that date.
The Overlord RAT delivers powerful attack tools: keystroke capture, screen grabbing, clipboard monitoring, hidden desktop, and even hidden persistence via a scheduled task that runs every five minutes. The task is backdated to January 1, 2020, to evade certain detection strategies.
MALFEX also incorporates detailed indicators for defenders: here are a few malicious package names and version ranges to watch for—function-flag (versions 2.3.5–2.3.9 for example), cdn-img-fetch (1.0.0–1.0.3), img-to-native, native-runner, tlxbnhd, tldriver, mxdriver.
Host artifacts include files dropped under local app directories (e.g. under ScopeSmart Technologies Inc), hidden scheduled tasks named “\Maiden”, and various executable names like AutoIt3.exe or node.exe. Attackers use backdated metadata and silent error suppression to stay under the radar.
What Developers & Security Teams Should Do
Relying solely on advisory feeds can be dangerous—some versions of MALFEX’s packages lack warnings or are only partially marked malicious. Security experts recommend: thoroughly auditing dependency trees and lockfiles; examining package cache and Windows endpoint behavior; isolating any host you suspect of infection; removing persistence; changing credentials exposed during the compromise; terminating exposed sessions; moving crypto assets; and blocking the eight identified malicious packages and their specific download URLs without disrupting shared hosting.
Indicators of compromise (IoCs) like SHA-256 hashes, package paths, and offending domains are available—for example `[email protected]–2.3.9` path names, and URLs serving “banner.png” or payloads like `setup.exe` embedded in image requests.
Even after packages are removed, credentials already stolen and persistence already established won’t disappear on their own. Remediation must include cleanup beyond just uninstalling npm modules.
As npm packages continue to be a common supply chain attack vector, MALFEX proves that image-based stealth techniques are evolving. Developers and security teams must treat every dependency—and its install and load scripts—with suspicion. Detecting malware today means watching for obscure image payloads, abnormal scheduled tasks, and unexpected outbound network patterns. The next major malware wave may use similar tricks with AI model packages or new registries. Stay alert—and verify before you trust.