Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NPM Malware Campaign Exceeds 40,000 Downloads

NPM Malware Campaign Exceeds 40,000 Downloads

Posted on October 6, 2026 By CWS

A significant NPM supply chain attack has resulted in over 40,000 downloads of malicious packages, according to findings by Checkmarx. Known as MALFEX, this campaign has been operational since August 2023, distributing harmful software such as the Overlord RAT and data-stealing tools.

Malicious Packages and Distribution

Since the initial malicious package was released, a total of 12 packages have been identified, with eight confirmed as harmful. Although five have been removed from the registry, three—function-flag, function-color, and cdn-img-fetch—remained available for installation as of early October.

Checkmarx highlighted function-flag for its extensive reach and potential threat, noting its presence on the platform since July 2025 with over 37,000 downloads, yet lacking proper advisories to warn users of its danger.

Vulnerabilities and Threat Vector

Six of the identified packages, including tlxbnhd and tldriver, have been flagged by Open Source Vulnerabilities (OSV) advisories. However, the advisories cover only partial versions of these threats, leaving gaps in protection for users.

Checkmarx’s analysis identified three distinct delivery paths within the campaign, each linked to the same threat actor but utilizing different infrastructures. The first path uses the Overlord RAT, which executes scripts during npm installation to conduct malicious activities on Windows systems.

Impacts and Security Concerns

The second path involves executing harmful code when the package loads, leading to the deployment of a Node.js information stealer named ‘movinlike’. This tool targets Discord clients, popular web browsers, and cryptocurrency wallets.

The third and most persistent path uses various versions of function-flag to download payloads from different locations. Interestingly, the installation process is designed to proceed even if the payload fails to download, with silent failures occurring on macOS and Linux, primarily affecting Windows users.

Checkmarx reports no dependency on widely-used packages, suggesting limited exposure to systems directly installing the malicious packages. The campaign does not target specific regions or organizations, making any system that installs the stealer susceptible to attack.

For further insights into cybersecurity threats, related articles discuss Linux backdoor vulnerabilities, macOS targeting via fake installers, and new developments in Windows botnet strategies.

Security Week News Tags:Checkmarx, cryptocurrency wallets, Cybersecurity, Discord clients, function-flag, InfoStealer, Malware, Node.js, NPM, open source vulnerabilities, OVERLORD RAT, supply chain attack, threat actor

Post navigation

Previous Post: New ClickFix Exploit Uses Browser Cache for Malware
Next Post: Meta and Microsoft Shift AI Strategy, Reduce Claude AI Use

Related Posts

European Commission Probes Cyberattack on IT Systems European Commission Probes Cyberattack on IT Systems Security Week News
Chrome to Turn HTTPS on by Default for Public Sites Chrome to Turn HTTPS on by Default for Public Sites Security Week News
WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users Security Week News
New York Seeking Public Opinion on Water Systems Cyber Regulations New York Seeking Public Opinion on Water Systems Cyber Regulations Security Week News
ClickFix Attack Exploits Fake Cloudflare Turnstile to Deliver Malware ClickFix Attack Exploits Fake Cloudflare Turnstile to Deliver Malware Security Week News
Join the Supply Chain & Risk Summit for Key Insights Join the Supply Chain & Risk Summit for Key Insights Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ClingSTUN Backdoor Targets IoT Devices for Remote Access
  • Apple Strengthens macOS Disk Access Amid AI Concerns
  • Security Flaws in LibreOffice and OpenOffice Unveiled
  • Meta and Microsoft Shift AI Strategy, Reduce Claude AI Use
  • NPM Malware Campaign Exceeds 40,000 Downloads

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ClingSTUN Backdoor Targets IoT Devices for Remote Access
  • Apple Strengthens macOS Disk Access Amid AI Concerns
  • Security Flaws in LibreOffice and OpenOffice Unveiled
  • Meta and Microsoft Shift AI Strategy, Reduce Claude AI Use
  • NPM Malware Campaign Exceeds 40,000 Downloads

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark