Malicious npm Packages Hit 40,000 Downloads as Advisory Gaps Persist

Eight malicious npm packages tied to MALFEX logged more than 40,000 downloads while gaps in security advisories left some threats uncovered.

Oct 6, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Eight malicious npm packages logged more than 40,000 downloads while security advisory coverage remained incomplete.

The MALFEX campaign has operated since August 2023 and delivers Windows-focused payloads. Checkmarx counted 40,767 downloads by Oct. 1, 2026, with function-flag alone accounting for 37,419. Researchers say that package has contained malicious code since July 2025.

Researchers at Checkmarx tied 12 npm packages to the apparent operator, eight of them malicious. function-flag and the related function-color package lacked Open Source Vulnerabilities (OSV) malware advisories in the firm’s analysis, leaving advisory-dependent security tools without records for those threats.

A similar August Shai-Hulud npm supply chain attack used malicious package releases and installation scripts to steal credentials, showing how trusted developer workflows can become malware delivery paths.

How MALFEX reached Windows systems

Three packages — tlxbnhd, tldriver, and mxdriver — delivered the Overlord remote access trojan. A second chain involving native-runner, img-to-native, and cdn-img-fetch delivered movinlike, a Node.js information stealer targeting browsers, Discord, Telegram, and cryptocurrency wallets.

The third path centered on function-flag, which used npm installation scripts to retrieve and execute additional payloads. function-color acted as a wrapper that pulled in function-flag as a dependency.

Advisory coverage did not fully reflect the malicious versions. The OSV record for cdn-img-fetch covers versions 1.0.0 and 1.0.1, while Checkmarx also classified versions 1.0.2 and 1.0.3 as malicious. Five of the eight packages had been unpublished or seized by npm by Oct. 1.

The 40,767-download total does not represent 40,767 confirmed infections. Registry counts can include automated and dependency-driven downloads, and researchers found no widely used legitimate packages depending on the MALFEX packages.

Other recent incidents show similar pressure on trusted development infrastructure. A September compromise of Coder’s module registry served malicious Terraform modules designed to steal cloud, CI/CD, AI, and SSH credentials.

Advertisement

Closing the advisory gap

Security teams should search dependency trees, manifests, and lockfiles for function-flag, function-color, cdn-img-fetch, img-to-native, native-runner, tlxbnhd, tldriver, and mxdriver. Windows developer systems and CI environments where malicious versions were installed should be treated as potentially compromised until investigated.

  • Block known malicious packages and investigate affected hosts. Isolate exposed systems, check for persistence and suspicious processes, and rotate potentially exposed credentials from a known-clean system.
  • Use locked, controlled builds. Commit lockfiles, use controlled CI installations, and review unexpected package or version changes before deployment.
  • Review dependencies before approval. Examine new and transitive dependencies, ownership changes, and lifecycle scripts before allowing them into build environments.
  • Restrict CI/CD privileges and outbound access. Minimize available secrets and unnecessary network connections to limit payload retrieval and credential theft.
  • Monitor package behavior as well as advisory status. Watch for suspicious processes, file writes, downloads, and outbound connections during installation and runtime.
  • Test incident response plans for supply chain attacks. Confirm teams can isolate systems, revoke credentials, preserve forensic evidence, and rebuild affected environments from trusted sources.

npm can restrict lifecycle-script execution, but that is not a complete defense because MALFEX also included code that could execute when a package was loaded.

Research into the wider software development toolchain shows why package controls need to sit alongside CI/CD, developer-tool, and provenance controls. MALFEX demonstrates how malicious code can exploit the window before advisory coverage catches up.

Read more: Compromised maintainer accounts offer another route into trusted package ecosystems, with Amazon linking four npm supply chain attacks to Sapphire Sleet.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.