Cyber Security News

Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.

MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages.

Linked to an apparent single operator active since August 2023, the campaign delivers Overlord RAT, the movinlike information stealer, and a separate downloader concealed inside an ASCII-art utility.

The largest contributor, function-flag, accounted for 37,419 downloads and has contained malicious code since July 2025. These figures measure registry activity, not confirmed infections.

Three packages remained installable at the documented checks: function-flag, function-color, and cdn-img-fetch.

Five others tlxbnhd, tldriver, mxdriver, img-to-native, and native-runner were unpublished or seized by npm. Four additional packages attributed to the operator contained no malicious code and served as cover.

The first delivery path uses tlxbnhd, tldriver, and mxdriver. Obfuscated preinstall and postinstall scripts retrieve a Windows executable from an image-hosting service, launch it, and delete themselves.

Although served as image/png, the payload is an IExpress archive containing a legitimately signed AutoIt interpreter and an encrypted script.

Successive XOR, RC4, and LZNT1 decoding stages reveal Overlord RAT. Code analysis indicated process hollowing into TapiUnattend.exe, with explorer.exe spoofed as the parent; researchers did not observe that injection at runtime.

Persistence relies on a scheduled task named Maiden, configured to execute every five minutes from a fake vendor directory.

Overlord supports keylogging, screen and clipboard capture, remote shells, and hidden-desktop access.

It can resolve command-and-control servers through encrypted Solana transaction memos, although the analyzed build contained no configured address or server list and generated no observed C2 traffic.

The second chain connects native-runner, img-to-native, and cdn-img-fetch. Instead of installation hooks, malicious code executes when packages load.

A GitHub-hosted PNG carries an encrypted executable appended after its image data, decrypted using the key malfexteam2027.

According to Checkmarx’s technical analysis, the malicious packages accumulated 40,767 downloads by October 1, 2026, including 3,017 during the preceding week.

npm Supply-Chain Campaign

The resulting Go downloader retrieves movinlike, a 64 MB Node.js stealer packaged as a Windows executable.

index.js (Source : Checkmarx).

It targets eight Discord clients, browser cookies and saved passwords, Telegram Desktop sessions, and cryptocurrency wallets, including MetaMask, Phantom, and Coinbase Wallet.

Stolen files are compressed, divided into 25 MB chunks, and transmitted through a Discord webhook.

The third path uses function-color to install function-flag. Its postinstall script invokes an ASCII-art function with the Bloody font, triggering a concealed download routine.

Version 1.7.3 retrieves node.exe into the Windows application-data directory and launches it with its window hidden.

That download host was unresponsive during analysis, leaving the payload unrecovered. Researchers found no evidence connecting this executable to movinlike.

Empty exception handling suppresses failures, while space-padded malicious lines push code beyond typical editor visibility.

Six malicious packages have OSV advisories, but coverage remains incomplete. Neither function-flag nor function-color had an advisory in the report.

MAL-2026-17320 covers cdn-img-fetch versions 1.0.0 and 1.0.1, omitting malicious releases 1.0.2 and 1.0.3. Advisory-only scanning can therefore miss affected dependencies.

Defenders should block all eight malicious packages and inspect dependency records. Windows systems that installed them require isolation, persistence removal, and credential rotation from a clean device.

Scheduled-task inspection is essential: the Overlord loader does not rely on registry Run keys.

Indicators of compromise

IndicatorRole
hxxps[:]//api.imghippo.com/files/hOG8244hc.pngOverlord RAT payload, served as image/png
www.image.comSecond Overlord RAT delivery domain (mxdriver)
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.pngStealer chain payload (PNG with appended data)
hxxp[:]//104.234.65.75:700/setup.exemovinlike download

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago