Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NPM Malware Campaign Exceeds 40,000 Downloads

NPM Malware Campaign Exceeds 40,000 Downloads

Posted on October 6, 2026 By CWS

A significant NPM supply chain attack has resulted in over 40,000 downloads of malicious packages, according to findings by Checkmarx. Known as MALFEX, this campaign has been operational since August 2023, distributing harmful software such as the Overlord RAT and data-stealing tools.

Malicious Packages and Distribution

Since the initial malicious package was released, a total of 12 packages have been identified, with eight confirmed as harmful. Although five have been removed from the registry, three—function-flag, function-color, and cdn-img-fetch—remained available for installation as of early October.

Checkmarx highlighted function-flag for its extensive reach and potential threat, noting its presence on the platform since July 2025 with over 37,000 downloads, yet lacking proper advisories to warn users of its danger.

Vulnerabilities and Threat Vector

Six of the identified packages, including tlxbnhd and tldriver, have been flagged by Open Source Vulnerabilities (OSV) advisories. However, the advisories cover only partial versions of these threats, leaving gaps in protection for users.

Checkmarx’s analysis identified three distinct delivery paths within the campaign, each linked to the same threat actor but utilizing different infrastructures. The first path uses the Overlord RAT, which executes scripts during npm installation to conduct malicious activities on Windows systems.

Impacts and Security Concerns

The second path involves executing harmful code when the package loads, leading to the deployment of a Node.js information stealer named ‘movinlike’. This tool targets Discord clients, popular web browsers, and cryptocurrency wallets.

The third and most persistent path uses various versions of function-flag to download payloads from different locations. Interestingly, the installation process is designed to proceed even if the payload fails to download, with silent failures occurring on macOS and Linux, primarily affecting Windows users.

Checkmarx reports no dependency on widely-used packages, suggesting limited exposure to systems directly installing the malicious packages. The campaign does not target specific regions or organizations, making any system that installs the stealer susceptible to attack.

For further insights into cybersecurity threats, related articles discuss Linux backdoor vulnerabilities, macOS targeting via fake installers, and new developments in Windows botnet strategies.

Security Week News Tags:Checkmarx, cryptocurrency wallets, Cybersecurity, Discord clients, function-flag, InfoStealer, Malware, Node.js, NPM, open source vulnerabilities, OVERLORD RAT, supply chain attack, threat actor

Post navigation

Previous Post: New ClickFix Exploit Uses Browser Cache for Malware
Next Post: Meta and Microsoft Shift AI Strategy, Reduce Claude AI Use

Related Posts

All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher Security Week News
Microsoft Awards  Million in Bug Bounties Microsoft Awards $20 Million in Bug Bounties Security Week News
SailPoint Plans Entro Acquisition for Enhanced Security SailPoint Plans Entro Acquisition for Enhanced Security Security Week News
Data Breach at Dutch Carrier Odido Affects Millions Data Breach at Dutch Carrier Odido Affects Millions Security Week News
The Loudest Voices in Security Often Have the Least to Lose The Loudest Voices in Security Often Have the Least to Lose Security Week News
RondoDox Botnet Exploiting React2Shell Vulnerability RondoDox Botnet Exploiting React2Shell Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Strengthens macOS Disk Access Amid AI Concerns
  • Security Flaws in LibreOffice and OpenOffice Unveiled
  • Meta and Microsoft Shift AI Strategy, Reduce Claude AI Use
  • NPM Malware Campaign Exceeds 40,000 Downloads
  • New ClickFix Exploit Uses Browser Cache for Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Strengthens macOS Disk Access Amid AI Concerns
  • Security Flaws in LibreOffice and OpenOffice Unveiled
  • Meta and Microsoft Shift AI Strategy, Reduce Claude AI Use
  • NPM Malware Campaign Exceeds 40,000 Downloads
  • New ClickFix Exploit Uses Browser Cache for Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark