Malfex npm Malware Hides Executables in PNG Files to Infect Windows Devs
Key Takeaways A sophisticated npm malware campaign, dubbed MALFEX, is targeting Windows developers. The attackers use novel methods, including embedding malicious executables within PNG image files,...
Key Takeaways
- A sophisticated npm malware campaign, dubbed MALFEX, is targeting Windows developers.
- The attackers use novel methods, including embedding malicious executables within PNG image files, to deliver remote access tools and information stealers.
- The campaign leverages multiple npm packages and three distinct infection chains, making detection challenging.
- Over 40,000 downloads of malicious packages have been recorded, indicating a broad reach among developers.
- Defenders must implement robust supply chain security measures and scrutinize package dependencies beyond basic advisory checks.
MALFEX Campaign Targets Windows Developers with Advanced Malware
A persistent and complex npm malware operation, identified as MALFEX, is actively compromising Windows development environments. This campaign deploys remote access Trojans (RATs), data exfiltration tools, and stealthy downloaders using an array of deceptive techniques, prominently featuring the embedding of executable code within seemingly innocuous PNG image files.
Table Of Content
- Key Takeaways
- MALFEX Campaign Targets Windows Developers with Advanced Malware
- Sophisticated Delivery: Executables in PNGs
- Method 1: PNG-Disguised Executables and Overlord RAT
- Method 2: Encrypted Payloads Appended to Genuine PNGs
- Method 3: ASCII Art Downloader
- Malware Capabilities: Remote Control, Account Theft, and Stealth
- Mitigation Challenges and Recommendations
- What You Should Do
- Indicators of Compromise (IoCs)
- URLs and Hosts
- SHA-256 Hashes
- Host Artifacts and Persistence
- Supporting Attribution Indicators
The attackers have utilized eight distinct malicious npm packages and three unique infection vectors since August 2023. By October 1, 2026, these packages collectively amassed 40,767 downloads, with 3,017 occurring in the week prior. It is important to note that download figures reflect package reach and do not directly translate to confirmed infections, as they include factors like repeated installations, dependency pulls, and systems incompatible with the Windows-specific payloads.
Checkmarx researchers identified the campaign in a report released on October 5. Their analysis linked twelve npm packages to a single operator, with four of these packages serving as benign cover for the malicious activity. The “MALFEX” moniker was consistently found across publisher accounts, repository metadata, package documentation, and even embedded in the image decryption key, suggesting a deliberate branding by the threat actor.
Sophisticated Delivery: Executables in PNGs
The MALFEX campaign employs several sophisticated delivery mechanisms, with the most notable involving the concealment of executables within image files.
Method 1: PNG-Disguised Executables and Overlord RAT
The initial infection vector involves three npm packages that execute hidden scripts either during or immediately after installation. These scripts retrieve a file served with an `image/png` content type, save it as a Windows executable, and then launch it. Despite the `image/png` label, the downloaded file is not a standard PNG but a Microsoft IExpress archive. Within this archive, a digitally signed AutoIt interpreter executes an encrypted script.
Through a multi-stage decoding process involving XOR, RC4, and LZNT1 compression, the script ultimately deploys the Overlord RAT. Code analysis revealed instructions for the RAT to inject itself into a legitimate, signed Windows process, attempting to mask its parent process as Explorer. However, this specific injection behavior was not observed during runtime testing by researchers.
Method 2: Encrypted Payloads Appended to Genuine PNGs
A second, distinct infection chain utilizes three different npm packages. This method fetches a legitimate PNG image that has encrypted executable data appended after its end-of-file marker. The malware then extracts this appended data and decrypts it using AES. The decrypted payload is a Go-based downloader, which subsequently retrieves “movinlike,” a 64 MB Node.js information stealer packaged as a Windows executable.
A critical aspect of this second method is that the malicious chain activates when the package is *loaded*, not through an install script. This distinction is significant because it bypasses security measures that disable npm lifecycle scripts, making it harder to prevent. This technique echoes previous npm attacks where RATs were hidden in PNGs, though those earlier campaigns typically embedded payloads within image pixels rather than appending them.
Method 3: ASCII Art Downloader
The third delivery path involves a downloader concealed within an ASCII art npm package. This downloader is triggered by a specific font value, with malicious code strategically placed beyond visible editor windows using extended sequences of spaces. Download failures are silently ignored. The latest analyzed payload for this specific chain was unavailable, and Checkmarx found no direct link between this downloader and the “movinlike” stealer.
Malware Capabilities: Remote Control, Account Theft, and Stealth
The payloads delivered by MALFEX are designed for extensive control and data exfiltration.
The Overlord RAT offers comprehensive remote control capabilities, including screen capture, keystroke logging, clipboard data collection, file system searches, and the execution of arbitrary remote commands. It also features a hidden desktop function. For persistence, its loader creates a scheduled task, named `Maiden`, configured to run every five minutes with a backdated start date of January 1, 2020. This tactic is designed to evade detection by security tools that only monitor registry startup keys.
The RAT can theoretically retrieve command-and-control (C2) server addresses from encrypted Solana transaction memos. However, the analyzed sample lacked a configured Solana address or server list, and researchers observed no C2 traffic, indicating this capability may not have been active in the tested infection.
The “movinlike” information stealer is highly focused on credential and session theft. It targets Discord tokens, browser cookies, saved browser passwords, Telegram sessions, and various cryptocurrency wallets. It achieves this by modifying Discord startup scripts, collecting account details, and transmitting stolen data in compressed chunks to a Discord webhook. This highlights the critical need for rigorous security checks of developer package installations, especially given past incidents like the StegaBin campaign.
Mitigation Challenges and Recommendations
As of Checkmarx’s October 1 snapshot, three malicious packages remained installable, with two lacking any malware advisories. Furthermore, one advisory only covered two of four malicious versions for a particular package. This indicates that organizations relying solely on advisory feeds may miss known compromised code.
What You Should Do
- Inspect Dependencies Thoroughly: Implement automated tools and manual review processes to scrutinize dependency trees, lockfiles, and package caches for any suspicious or unknown packages, particularly those with low download counts or recent publication dates.
- Isolate and Preserve: If an affected package is discovered, immediately isolate the compromised host. Preserve system images and logs for forensic analysis.
- Remove Persistence: Identify and remove all forms of persistence established by the malware, including scheduled tasks (e.g., `Maiden`), modified startup scripts, and any dropped executables.
- Reset Credentials: Change all exposed passwords from a clean, uncompromised system. This includes developer accounts, version control systems, and any services accessed from the infected environment.
- Secure Messaging and Crypto: End all active Telegram sessions and transfer any cryptocurrency funds from exposed wallets to new, secure wallets.
- Block Malicious Indicators: Implement network blocks for the specific malicious package versions, URLs, and hosts identified in the IoCs section, being careful not to block entire shared hosting services.
- Review Internal Registries: Audit internal npm registries and mirrors to ensure no malicious copies of these packages are present, preventing re-infection.
- Monitor Account Activity: Continuously monitor developer account activity for unusual logins or actions that could indicate compromise.
Indicators of Compromise (IoCs)
| Package | Malicious versions |
|---|---|
function-flag |
1.7.3, 4.0.0, 3.0.0, 2.3.5–2.3.9 |
function-color |
1.7.3, 1.0.0 |
cdn-img-fetch |
1.0.0–1.0.3 |
img-to-native |
1.0.0–1.0.3 |
native-runner |
1.0.0–1.0.3 |
tlxbnhd |
0.0.1 |
tldriver |
0.0.1 |
mxdriver |
0.0.1, 0.0.2 |
Note that [email protected] is explicitly identified as not malicious by Checkmarx.
URLs and Hosts
| Source-listed indicator | Role |
|---|---|
hxxps[:]//api.imghippo.com/files/hOG8244hc.png |
Overlord loader served as PNG |
www.image.com |
Second Overlord delivery domain associated with mxdriver |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png |
Stealer-chain image; used by cdn-img-fetch versions 1.0.0–1.0.2 |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.jpg |
[email protected] payload |
hxxp[:]//104.234.65.75:700/setup.exe |
movinlike download |
hxxp[:]//104.234.65.75/setup.exe |
Alternate movinlike download path |
hxxps[:]//cdnzona.discloud.app/node.exe |
[email protected] payload |
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe |
[email protected] payload |
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… |
[email protected]; incomplete in the source’s IoC table |
hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe |
[email protected] payload |
hxxps[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe |
[email protected] payload |
hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe |
[email protected] payload |
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe |
[email protected] payload |
hxxps[:]//51.137.158.178/download |
[email protected] payload |
discord.com/api/webhooks/1553545982975811594/… |
movinlike data-theft webhook; token omitted by the source |
Both HTTP and HTTPS variants of the listed IP addresses and domains were observed. It is advised to block specific malicious paths rather than entire shared service domains.
SHA-256 Hashes
| Artifact | SHA-256 |
|---|---|
| Overlord RAT loader served as PNG | 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793 |
Signed AutoIt3.exe from archive |
5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7 |
Encrypted Oxygen.a3x / h.a3x script |
fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67 |
| Decoded Overlord RAT | 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210 |
Current banner.png |
4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106 |
| Stealer-chain downloader, September 25 | 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849 |
| Stealer-chain downloader, September 25 | e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4 |
| Stealer-chain downloader, September 25 | ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807 |
| Stealer-chain downloader, September 26 | 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b |
tlxbnhd/scripts/postinstall.js |
7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e |
| movinlike | c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437 |
[email protected]/index.js |
c7cf2323e4923428984297db7715d75fec5b964fe65c325b53e3fa360f3b8d86 |
[email protected]/index.js and version 1.0.1 |
430300450f5acbd69c29f02d8c2e243f7d1d6202d1826f6e4d7715f95c47299b |
[email protected]/index.js |
4cba0c785e66d517eabd0164f34a9c2d04549da93b5ee3eebdce5558daa2f47c |
[email protected]/index.js |
5c933aa533721fa293b284170dd4611a4d88f88cc89f2d9c28ea4e22305b1f75 |
[email protected] — banner.jpg |
8f7ed69fb5505b57f06e673826779d459f7735739756de73a6d3347a9c8ea0cc |
[email protected]/index.js |
d54853d6be467567d9f22d7f22ac48214df52c1f9c7a503930e901286423044a |
[email protected]/example.js |
886b84f83a0f760e664046ba40d8c800b7d0cf72190e13ca031ee5cf50f45bee |
Note that movinlike can be readily recompiled, so hash checks should be complemented by broader file, task, and network analysis. The signed AutoIt interpreter is legitimate software; its presence alone does not confirm infection without further contextual evidence.
Host Artifacts and Persistence
| Indicator | Meaning |
|---|---|
%LOCALAPPDATA%ScopeSmart Technologies Inc |
Overlord loader directory |
%LOCALAPPDATA%ScopeSmart Technologies IncAutoIt3.exe |
Interpreter used by the loader |
%LOCALAPPDATA%ScopeSmart Technologies Inch.a3x |
Encrypted AutoIt script |
%LOCALAPPDATA%ScopeSmart Technologies IncSmartScope.vbs |
Associated script |
Scheduled task Maiden |
Overlord persistence |
Task command "AutoIt3.exe" "h.a3x" |
Scheduled execution |
| Task interval: every five minutes, no end time | Persistence timing |
Task start date: 1/1/2020 |
Backdated task metadata |
Task author: Welcome; comment: Wichita |
Associated task metadata |
<package dir>gldriver_pre_core.exe |
Dropped Overlord payload, deleted after launch |
<package dir>gldriver_pre_asset.exe |
Dropped Overlord payload, deleted after launch |
%APPDATA%MicrosoftWindowsnode_runtime_helper.exe |
Decrypted stealer-chain downloader |
%TEMP%._cif_data |
Stealer-chain intermediate file |
%APPDATA%node.exe |
[email protected] payload |
Supporting Attribution Indicators
| Indicator | Source context |
|---|---|
malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4 |
npm publisher accounts |
corpmalfex[@]gmail.com |
Payload repository Git author email |
malfexteam2027 |
Stealer-chain AES decryption key |
Murizada |
Owner name credited in the package README |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.