CloudSEK’s Global Threat Intelligence team has uncovered MALFEX, a long-running npm supply-chain campaign linked to a single operator that used malicious packages to deploy RAT, steal credentials and maintain persistence on Windows systems.
What makes the campaign notable is that parts of the infrastructure remained active even after related packages were seized, while one malicious npm postinstall went undetected for 14 months.
Key findings:
- CloudSEK linked multiple npm packages and a GitHub payload repository to the same MALFEX operator.
- function-flag remained malicious and installable for 14 months without an advisory; its companion package function-color also remained live and unflagged.
- cdn-img-fetch remained reachable even after npm seized its parent package, highlighting a gap in dependency-level takedowns.
- One delivery chain deployed Overlord, a Go-based RAT capable of screen capture, keylogging, remote shell access and hidden desktop activity.
- CloudSEK identified a Solana blockchain-based C2 mechanism, allowing operators to rotate command-and-control infrastructure through encrypted on-chain messages.
- A second malware chain targeted Discord, Telegram, browser credentials, cookies and cryptocurrency wallets, with stolen data exfiltrated through Discord infrastructure.
The research highlights how malicious npm packages can survive conventional advisory and takedown processes by splitting functionality across dependencies, wrappers and external infrastructure.
Read the full report:
https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
Related
This entry was posted on September 30, 2026 at 9:01 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Malicious npm postinstall stayed undetected for 14 months CloudSEK finds
CloudSEK’s Global Threat Intelligence team has uncovered MALFEX, a long-running npm supply-chain campaign linked to a single operator that used malicious packages to deploy RAT, steal credentials and maintain persistence on Windows systems.
What makes the campaign notable is that parts of the infrastructure remained active even after related packages were seized, while one malicious npm postinstall went undetected for 14 months.
Key findings:
The research highlights how malicious npm packages can survive conventional advisory and takedown processes by splitting functionality across dependencies, wrappers and external infrastructure.
Read the full report:
https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
Share this:
Like this:
Related
This entry was posted on September 30, 2026 at 9:01 am and is filed under Commentary with tags CloudSEK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.