A persistent malware campaign known as MALFEX has been targeting NPM packages since August 2023, resulting in over 40,000 downloads. Security firm Checkmarx has reported that the campaign involves 12 packages, eight of which are malicious. Although five packages have been removed, three remain accessible, specifically function-flag, function-color, and cdn-img-fetch. Function-flag is particularly concerning as it has amassed over 37,000 downloads without advisory warnings.

The campaign employs three distinct delivery methods, all linked to the same threat actor but using separate infrastructures. The first method involves loaders for the Overlord RAT, which is compatible with Windows, macOS, and Linux, although the payload only operates on Windows. This RAT provides extensive capabilities for the attacker, including screen capture and remote shell access. The second method executes malicious code to install the Node.js stealer 'movinlike', which targets popular browsers, Discord clients, and cryptocurrency wallets. The third approach uses a downloader in the function-flag package to retrieve a payload from an external source.

Checkmarx has also noted that the installation process can complete without downloading the payload, especially on macOS and Linux, thereby primarily affecting Windows users. Despite the widespread distribution of these packages, no legitimate software depends on them, limiting exposure to systems that directly installed the malicious packages. Checkmarx found no specific geographic or organizational targets, indicating that the malware targets anyone who installs the affected packages.