Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
October 9, 2026
Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
October 9, 2026
Top 10 Container Image Scanners for 2026
October 9, 2026
Home/CyberSecurity News/Malfex npm Malware Hides Executables in PNG Files to Infect Windows Devs
CyberSecurity News

Malfex npm Malware Hides Executables in PNG Files to Infect Windows Devs

Key Takeaways A sophisticated npm malware campaign, dubbed MALFEX, is targeting Windows developers. The attackers use novel methods, including embedding malicious executables within PNG image files,...

Sarah simpson
Sarah simpson
October 8, 2026 6 Min Read
24 0

Key Takeaways

  • A sophisticated npm malware campaign, dubbed MALFEX, is targeting Windows developers.
  • The attackers use novel methods, including embedding malicious executables within PNG image files, to deliver remote access tools and information stealers.
  • The campaign leverages multiple npm packages and three distinct infection chains, making detection challenging.
  • Over 40,000 downloads of malicious packages have been recorded, indicating a broad reach among developers.
  • Defenders must implement robust supply chain security measures and scrutinize package dependencies beyond basic advisory checks.

MALFEX Campaign Targets Windows Developers with Advanced Malware

A persistent and complex npm malware operation, identified as MALFEX, is actively compromising Windows development environments. This campaign deploys remote access Trojans (RATs), data exfiltration tools, and stealthy downloaders using an array of deceptive techniques, prominently featuring the embedding of executable code within seemingly innocuous PNG image files.

Table Of Content

  • Key Takeaways
  • MALFEX Campaign Targets Windows Developers with Advanced Malware
  • Sophisticated Delivery: Executables in PNGs
  • Method 1: PNG-Disguised Executables and Overlord RAT
  • Method 2: Encrypted Payloads Appended to Genuine PNGs
  • Method 3: ASCII Art Downloader
  • Malware Capabilities: Remote Control, Account Theft, and Stealth
  • Mitigation Challenges and Recommendations
  • What You Should Do
  • Indicators of Compromise (IoCs)
  • URLs and Hosts
  • SHA-256 Hashes
  • Host Artifacts and Persistence
  • Supporting Attribution Indicators

The attackers have utilized eight distinct malicious npm packages and three unique infection vectors since August 2023. By October 1, 2026, these packages collectively amassed 40,767 downloads, with 3,017 occurring in the week prior. It is important to note that download figures reflect package reach and do not directly translate to confirmed infections, as they include factors like repeated installations, dependency pulls, and systems incompatible with the Windows-specific payloads.

Checkmarx researchers identified the campaign in a report released on October 5. Their analysis linked twelve npm packages to a single operator, with four of these packages serving as benign cover for the malicious activity. The “MALFEX” moniker was consistently found across publisher accounts, repository metadata, package documentation, and even embedded in the image decryption key, suggesting a deliberate branding by the threat actor.

Sophisticated Delivery: Executables in PNGs

The MALFEX campaign employs several sophisticated delivery mechanisms, with the most notable involving the concealment of executables within image files.

Method 1: PNG-Disguised Executables and Overlord RAT

The initial infection vector involves three npm packages that execute hidden scripts either during or immediately after installation. These scripts retrieve a file served with an `image/png` content type, save it as a Windows executable, and then launch it. Despite the `image/png` label, the downloaded file is not a standard PNG but a Microsoft IExpress archive. Within this archive, a digitally signed AutoIt interpreter executes an encrypted script.

Through a multi-stage decoding process involving XOR, RC4, and LZNT1 compression, the script ultimately deploys the Overlord RAT. Code analysis revealed instructions for the RAT to inject itself into a legitimate, signed Windows process, attempting to mask its parent process as Explorer. However, this specific injection behavior was not observed during runtime testing by researchers.

Method 2: Encrypted Payloads Appended to Genuine PNGs

A second, distinct infection chain utilizes three different npm packages. This method fetches a legitimate PNG image that has encrypted executable data appended after its end-of-file marker. The malware then extracts this appended data and decrypts it using AES. The decrypted payload is a Go-based downloader, which subsequently retrieves “movinlike,” a 64 MB Node.js information stealer packaged as a Windows executable.

A critical aspect of this second method is that the malicious chain activates when the package is *loaded*, not through an install script. This distinction is significant because it bypasses security measures that disable npm lifecycle scripts, making it harder to prevent. This technique echoes previous npm attacks where RATs were hidden in PNGs, though those earlier campaigns typically embedded payloads within image pixels rather than appending them.

Method 3: ASCII Art Downloader

The third delivery path involves a downloader concealed within an ASCII art npm package. This downloader is triggered by a specific font value, with malicious code strategically placed beyond visible editor windows using extended sequences of spaces. Download failures are silently ignored. The latest analyzed payload for this specific chain was unavailable, and Checkmarx found no direct link between this downloader and the “movinlike” stealer.

Malware Capabilities: Remote Control, Account Theft, and Stealth

The payloads delivered by MALFEX are designed for extensive control and data exfiltration.

The Overlord RAT offers comprehensive remote control capabilities, including screen capture, keystroke logging, clipboard data collection, file system searches, and the execution of arbitrary remote commands. It also features a hidden desktop function. For persistence, its loader creates a scheduled task, named `Maiden`, configured to run every five minutes with a backdated start date of January 1, 2020. This tactic is designed to evade detection by security tools that only monitor registry startup keys.

The RAT can theoretically retrieve command-and-control (C2) server addresses from encrypted Solana transaction memos. However, the analyzed sample lacked a configured Solana address or server list, and researchers observed no C2 traffic, indicating this capability may not have been active in the tested infection.

The “movinlike” information stealer is highly focused on credential and session theft. It targets Discord tokens, browser cookies, saved browser passwords, Telegram sessions, and various cryptocurrency wallets. It achieves this by modifying Discord startup scripts, collecting account details, and transmitting stolen data in compressed chunks to a Discord webhook. This highlights the critical need for rigorous security checks of developer package installations, especially given past incidents like the StegaBin campaign.

Mitigation Challenges and Recommendations

As of Checkmarx’s October 1 snapshot, three malicious packages remained installable, with two lacking any malware advisories. Furthermore, one advisory only covered two of four malicious versions for a particular package. This indicates that organizations relying solely on advisory feeds may miss known compromised code.

What You Should Do

  • Inspect Dependencies Thoroughly: Implement automated tools and manual review processes to scrutinize dependency trees, lockfiles, and package caches for any suspicious or unknown packages, particularly those with low download counts or recent publication dates.
  • Isolate and Preserve: If an affected package is discovered, immediately isolate the compromised host. Preserve system images and logs for forensic analysis.
  • Remove Persistence: Identify and remove all forms of persistence established by the malware, including scheduled tasks (e.g., `Maiden`), modified startup scripts, and any dropped executables.
  • Reset Credentials: Change all exposed passwords from a clean, uncompromised system. This includes developer accounts, version control systems, and any services accessed from the infected environment.
  • Secure Messaging and Crypto: End all active Telegram sessions and transfer any cryptocurrency funds from exposed wallets to new, secure wallets.
  • Block Malicious Indicators: Implement network blocks for the specific malicious package versions, URLs, and hosts identified in the IoCs section, being careful not to block entire shared hosting services.
  • Review Internal Registries: Audit internal npm registries and mirrors to ensure no malicious copies of these packages are present, preventing re-infection.
  • Monitor Account Activity: Continuously monitor developer account activity for unusual logins or actions that could indicate compromise.

Indicators of Compromise (IoCs)

Package Malicious versions
function-flag 1.7.3, 4.0.0, 3.0.0, 2.3.5–2.3.9
function-color 1.7.3, 1.0.0
cdn-img-fetch 1.0.0–1.0.3
img-to-native 1.0.0–1.0.3
native-runner 1.0.0–1.0.3
tlxbnhd 0.0.1
tldriver 0.0.1
mxdriver 0.0.1, 0.0.2

Note that [email protected] is explicitly identified as not malicious by Checkmarx.

URLs and Hosts

Source-listed indicator Role
hxxps[:]//api.imghippo.com/files/hOG8244hc.png Overlord loader served as PNG
www.image.com Second Overlord delivery domain associated with mxdriver
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png Stealer-chain image; used by cdn-img-fetch versions 1.0.0–1.0.2
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.jpg [email protected] payload
hxxp[:]//104.234.65.75:700/setup.exe movinlike download
hxxp[:]//104.234.65.75/setup.exe Alternate movinlike download path
hxxps[:]//cdnzona.discloud.app/node.exe [email protected] payload
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe [email protected] payload
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… [email protected]; incomplete in the source’s IoC table
hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe [email protected] payload
hxxps[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe [email protected] payload
hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe [email protected] payload
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe [email protected] payload
hxxps[:]//51.137.158.178/download [email protected] payload
discord.com/api/webhooks/1553545982975811594/… movinlike data-theft webhook; token omitted by the source

Both HTTP and HTTPS variants of the listed IP addresses and domains were observed. It is advised to block specific malicious paths rather than entire shared service domains.

SHA-256 Hashes

Artifact SHA-256
Overlord RAT loader served as PNG 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793
Signed AutoIt3.exe from archive 5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7
Encrypted Oxygen.a3x / h.a3x script fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67
Decoded Overlord RAT 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210
Current banner.png 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106
Stealer-chain downloader, September 25 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849
Stealer-chain downloader, September 25 e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4
Stealer-chain downloader, September 25 ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807
Stealer-chain downloader, September 26 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b
tlxbnhd/scripts/postinstall.js 7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e
movinlike c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437
[email protected]/index.js c7cf2323e4923428984297db7715d75fec5b964fe65c325b53e3fa360f3b8d86
[email protected]/index.js and version 1.0.1 430300450f5acbd69c29f02d8c2e243f7d1d6202d1826f6e4d7715f95c47299b
[email protected]/index.js 4cba0c785e66d517eabd0164f34a9c2d04549da93b5ee3eebdce5558daa2f47c
[email protected]/index.js 5c933aa533721fa293b284170dd4611a4d88f88cc89f2d9c28ea4e22305b1f75
[email protected] — banner.jpg 8f7ed69fb5505b57f06e673826779d459f7735739756de73a6d3347a9c8ea0cc
[email protected]/index.js d54853d6be467567d9f22d7f22ac48214df52c1f9c7a503930e901286423044a
[email protected]/example.js 886b84f83a0f760e664046ba40d8c800b7d0cf72190e13ca031ee5cf50f45bee

Note that movinlike can be readily recompiled, so hash checks should be complemented by broader file, task, and network analysis. The signed AutoIt interpreter is legitimate software; its presence alone does not confirm infection without further contextual evidence.

Host Artifacts and Persistence

Indicator Meaning
%LOCALAPPDATA%ScopeSmart Technologies Inc Overlord loader directory
%LOCALAPPDATA%ScopeSmart Technologies IncAutoIt3.exe Interpreter used by the loader
%LOCALAPPDATA%ScopeSmart Technologies Inch.a3x Encrypted AutoIt script
%LOCALAPPDATA%ScopeSmart Technologies IncSmartScope.vbs Associated script
Scheduled task Maiden Overlord persistence
Task command "AutoIt3.exe" "h.a3x" Scheduled execution
Task interval: every five minutes, no end time Persistence timing
Task start date: 1/1/2020 Backdated task metadata
Task author: Welcome; comment: Wichita Associated task metadata
<package dir>gldriver_pre_core.exe Dropped Overlord payload, deleted after launch
<package dir>gldriver_pre_asset.exe Dropped Overlord payload, deleted after launch
%APPDATA%MicrosoftWindowsnode_runtime_helper.exe Decrypted stealer-chain downloader
%TEMP%._cif_data Stealer-chain intermediate file
%APPDATA%node.exe [email protected] payload

Supporting Attribution Indicators

Indicator Source context
malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4 npm publisher accounts
corpmalfex[@]gmail.com Payload repository Git author email
malfexteam2027 Stealer-chain AES decryption key
Murizada Owner name credited in the package README

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Cisco Nexus Flaws Allow Root-Level Remote Code Execution

Next Post

wolfSSH 1.6.0 Patches Critical MITM Host Key Verification Bypass Vulnerability

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Anthropic’s New OSS Scanner Identifies Open-Source Vulnerabilities
October 9, 2026
Top 10 IaC Security Tools for 2026
October 9, 2026
Microsoft: PKI, HSMs, Security Appliances Must Prepare for Post-Quantum Authentication
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us