npm malware hides Windows downloads in dependency installs
AI-generated image

npm malware hides Windows downloads in dependency installs

npm malware in eight packages delivers remote-control tools and data stealers to Windows systems, with three packages still available in the source report.

npm malware concealed in software packages is delivering remote-control tools and information stealers to Windows computers, according to research by CloudSEK and Checkmarx. The companies call the campaign MALFEX and assess that a single operator appears to have published 12 packages since August 2023, with eight identified as malicious. For businesses that use npm, a service for distributing reusable JavaScript software, the exposure sits in the software their developers install, not just in the finished website.

The eight identified packages are tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color and cdn-img-fetch. The source report lists function-flag, function-color and cdn-img-fetch as still available. Together, the eight packages recorded 40,767 downloads, including 37,419 for function-flag alone. Those are download counts, not a confirmed total of infected computers or affected businesses.

Function-flag was initially published in July 2024, and its most recent release in the report dates to August 4, 2025. Its project description contains a Portuguese welcome message crediting the Malfex team and naming Murizada as its owner. This ordinary-looking package presentation accompanies code that can retrieve and run additional software during installation.

The researchers describe three delivery routes: a loader, meaning software that starts another malicious program, for the Overlord remote access trojan (RAT); a route delivering the movinlike information stealer; and a downloader that retrieves a further payload, or program used in the attack. A RAT gives an operator remote control of a compromised computer. Overlord is openly available software written in the Go programming language and uses Solana blockchain transactions to obtain its command-and-control address, the destination through which an attacker directs the malware.

Three packages, tlxbnhd, tldriver and mxdriver, serve as Overlord loaders. They use lifecycle hooks, scripts that run automatically at particular stages of a package's installation or use, to download and execute a Windows program. This is the central risk of this npm malware campaign: installing a software component can also start code that the person installing it did not intend to run.

Another route involves packages including img-to-native, which relies on cdn-img-fetch to retrieve and execute a program written in Go. That program then fetches movinlike, a stealer built with Node.js, software that runs JavaScript outside a web browser. The stealer targets sensitive information associated with Discord, web browsers, Telegram and cryptocurrency wallets. The source does not quantify how much information was stolen or identify individual victims.

Function-flag has a postinstall hook, an automatic script executed after installation, that runs JavaScript to fetch another program from a remote server. Researchers found that different package versions used different download locations. Function-color does not contain its own payload; instead, it declares function-flag as a dependency, a separate package installed because another package requires it. Checking only the package deliberately selected by a developer can therefore miss the component responsible for the download.

Checkmarx describes version 1.7.3 as the latest version in its analysis. Its postinstall script executes example.js, which invokes a function for making pictures from text characters with a font setting called Bloody. That setting activates a concealed download routine. The routine retrieves node.exe from cdnzona.discloud.app, hosted on a Brazilian application hosting service, writes it to %APPDATA%\node.exe in the Windows user's application-data location, and launches it with its window hidden. The filename alone should not be treated as evidence that this downloaded program is legitimate Node.js software.

CloudSEK points to Portuguese-language material, a -0300 time-zone offset in git commits, which record software changes, and a common Brazilian handle in the operator's GitHub display name and email as clues about the operator's linguistic background. It explicitly does not treat these clues as evidence that Brazil is the target. According to CloudSEK, distribution involves npm and Discord, both global services, and targeting by the subsequently delivered malware is opportunistic. The assessment that one person is responsible remains an assessment, not a confirmed identity.

For website owners, the practical question is whether anyone maintaining their site or business software installed these packages on a Windows computer. The report describes Windows infection routes, not proof that every website using JavaScript is compromised. Ask the responsible developer or IT provider to check both directly chosen packages and the additional packages they bring in. AEU-I's security-first IT, infrastructure and consulting services are relevant to businesses seeking help reviewing this kind of software dependency risk. If a listed package is found, have the affected computer assessed rather than assuming that removing the package also removes programs it has already downloaded.

How to Protect Yourself

  1. Send the eight package names in this article to your website developer or IT provider and ask whether any were installed, including automatically with other software.
  2. Ask your developer to stop using any listed package until your IT provider has checked the affected Windows computer.
  3. If your IT provider confirms an infection, use a different, trusted device to change passwords for accounts used on that computer.
  4. Turn on two-step sign-in in the security settings of your email, Discord and Telegram accounts where available.

Terms Explained

  • npm A service developers use to obtain and share reusable JavaScript software packages.
  • remote access trojan (RAT) A malicious program that lets someone else control an infected computer remotely.
  • lifecycle hooks Automatic instructions that run at defined stages when a software package is installed or used.
  • dependency An additional software package that another package needs to work.
  • postinstall hook An instruction that automatically runs after a software package is installed.
  • command-and-control address An online destination malware uses to receive directions from its operator.
  • information stealer Malicious software designed to collect private information from a computer.

Related AEU services

  • AEU-I IT and security consulting