MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months

· Original article ↗

Summary

CloudSek links a set of malicious npm packages to one operator and two delivery arms, including active packages that remained available after a related package was seized. The campaign steals credentials and data from Windows systems.

Key points

  • The report links at least 12 npm packages and a GitHub payload repository to one operator; some packages were malicious while others served as cover.
  • Three packages lacked advisories: function-flag, cdn-img-fetch, and function-color. The report says they were still active or installable at the time of writing.
  • One delivery arm uses npm packages to install an AutoIt-based loader and the Overlord Go RAT, with a live Solana-based command-and-control resolver in the recovered build.
  • A second arm retrieves an encrypted payload from GitHub and downloads a Node.js bundle that injects into Discord clients, collects browser and Telegram data, and exfiltrates it through a Discord webhook.
  • Amazon Inspector advisories covered five packages, but the report says cdn-img-fetch remained reachable after npm seized its parent package, img-to-native.
  • Recommended defenses include blocking the three unadvised packages, monitoring specified persistence artifacts, restricting outbound access to identified payload hosts and the webhook, and reviewing dependencies during package takedowns.

Article Details

Attack Vectors
  • The operator published malicious npm packages that execute during postinstall. function-color also pulls in the malicious function-flag package as a dependency.
  • Delivery Arm A downloads a Windows executable disguised as image/png, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and an encrypted script, and executes an overlord-client build.
  • Delivery Arm B retrieves a PNG polyglot from a GitHub repository, decrypts an embedded payload using the malfexteam2027 key, and fetches the movinlike Node.js bundle. The bundle injects into Discord clients, harvests browser and Telegram tdata, and exfiltrates data to a Discord webhook.
Defensive Notes
  • Block installation of function-flag, cdn-img-fetch, and function-color.
  • Alert on %LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe and the \Maiden scheduled task.
  • Restrict outbound connections to the identified payload hosts and Discord webhook.
  • Inspect declared dependencies when taking down a registry package; cdn-img-fetch remained installable after npm seized its parent package, img-to-native.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEapi[.]imghippo[.]comImage-host endpoint identified as hosting the Delivery Arm A payload.
IPV4104[.]234[.]65[.]75Host at port 700 from which Delivery Arm B fetches the movinlike Node.js bundle.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

Related Articles