A long-running malware campaign on the npm registry is using malicious JavaScript packages to compromise Windows systems with remote-access malware, information stealers and additional payloads. Researchers have linked the operation, known as MALFEX, to an apparent single operator active on npm since August 2023.
The operator has published 12 packages, eight of which were found to contain malicious code. Together, the packages had recorded 40,767 downloads by October 1. However, those figures represent package downloads rather than confirmed infections.
MALFEX currently uses three separate infection chains. The first delivers the Overlord Remote Access Trojan through packages including tlxbnhd, tldriver and mxdriver.
Malicious installation scripts download and execute a Windows payload disguised as an image. Overlord can capture screenshots, keystrokes and clipboard data, search files and provide attackers with remote shell access. It also establishes persistence through a scheduled Windows task named “Maiden.”
A second chain involves native-runner, img-to-native and cdn-img-fetch.
Instead of relying on an npm installation script, the malicious code executes when the package is loaded. Data hidden inside an image is decrypted to produce a downloader, which retrieves movinlike, a Node.js information stealer. The malware targets Discord accounts, browser credentials, Telegram session data and cryptocurrency wallets before sending stolen information to an attacker-controlled Discord webhook.
The third and longest-running chain revolves around function-flag. Its malicious versions contain code that downloads Windows executables from changing external locations. In version 1.7.3, a hidden routine triggered during installation downloads node.exe and executes it from the user’s application-data directory. function-color serves as a wrapper that installs function-flag.
Three malicious packages remained installable as of September 29: function-flag, function-color and cdn-img-fetch. function-flag accounted for 37,419 downloads, making it by far the most widely downloaded package in the campaign. Despite that activity, it had no security advisory. function-color also lacked an advisory, while the advisory for cdn-img-fetch covered only versions 1.0.0 and 1.0.1, leaving malicious versions 1.0.2 and 1.0.3 outside its coverage.
The campaign also uses several techniques to make detection harder. Malicious code can be hidden beyond the visible area of a typical editor, failed downloads may be suppressed without generating installation errors, and the attacker has published benign packages alongside the malicious ones.
Security teams should block all eight identified malicious packages and check dependency trees and lockfiles for them.
Any Windows system where one was installed should be treated as potentially compromised, isolated from the network and investigated. Organizations should also remove persistence mechanisms and rotate credentials from a clean device if sensitive accounts were used on the affected machine.
MALFEX highlights the risk of relying solely on npm advisory feeds: malicious packages can remain installable even when related packages have been removed, while some dangerous versions may have no advisory coverage at all.
Read the original article:
