A significant NPM supply chain attack has resulted in over 40,000 downloads of malicious packages, according to findings by Checkmarx. Known as MALFEX, this campaign has been operational since August 2023, distributing harmful software such as the Overlord RAT and data-stealing tools.
Malicious Packages and Distribution
Since the initial malicious package was released, a total of 12 packages have been identified, with eight confirmed as harmful. Although five have been removed from the registry, three—function-flag, function-color, and cdn-img-fetch—remained available for installation as of early October.
Checkmarx highlighted function-flag for its extensive reach and potential threat, noting its presence on the platform since July 2025 with over 37,000 downloads, yet lacking proper advisories to warn users of its danger.
Vulnerabilities and Threat Vector
Six of the identified packages, including tlxbnhd and tldriver, have been flagged by Open Source Vulnerabilities (OSV) advisories. However, the advisories cover only partial versions of these threats, leaving gaps in protection for users.
Checkmarx’s analysis identified three distinct delivery paths within the campaign, each linked to the same threat actor but utilizing different infrastructures. The first path uses the Overlord RAT, which executes scripts during npm installation to conduct malicious activities on Windows systems.
Impacts and Security Concerns
The second path involves executing harmful code when the package loads, leading to the deployment of a Node.js information stealer named ‘movinlike’. This tool targets Discord clients, popular web browsers, and cryptocurrency wallets.
The third and most persistent path uses various versions of function-flag to download payloads from different locations. Interestingly, the installation process is designed to proceed even if the payload fails to download, with silent failures occurring on macOS and Linux, primarily affecting Windows users.
Checkmarx reports no dependency on widely-used packages, suggesting limited exposure to systems directly installing the malicious packages. The campaign does not target specific regions or organizations, making any system that installs the stealer susceptible to attack.
For further insights into cybersecurity threats, related articles discuss Linux backdoor vulnerabilities, macOS targeting via fake installers, and new developments in Windows botnet strategies.
