MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders.

The attack uses eight malicious packages and three separate delivery paths, including a Windows executable disguised as a PNG and an encrypted program hidden after real image data.

The operator has published packages since August 2023. Across the eight malicious packages, npm recorded 40,767 downloads by October 1, 2026, including 3,017 during the previous week.

Those numbers show package reach, not confirmed infections: downloads can include repeat installs, dependencies, and systems that cannot run the Windows payloads.

Checkmarx researchers identified the campaign in an October 5 report. They linked twelve packages to what appears to be one operator, with four clean packages used as cover.

The MALFEX name appeared in publisher accounts, repository records, and package documentation, while the image decryption key also carried the same branding.

MALFEX npm Malware Hides Executables in PNG Files

The first delivery path uses three packages that run hidden scripts before or after installation. These scripts fetch a file served as image/png, save it as a Windows executable, and launch it.

Despite its image label, the download is a Microsoft IExpress archive rather than a normal PNG. Inside the archive, a signed AutoIt interpreter runs an encrypted script.

postinstall[.]js (Source - Checkmarx)
postinstall[.]js (Source – Checkmarx)

Several decoding steps, including XOR, RC4, and LZNT1 compression, reveal Overlord RAT. Code analysis showed instructions to inject the RAT into a signed Windows process while making Explorer appear to be its parent. Researchers did not observe that injection during runtime testing.

The second path works differently. A chain of three packages fetches a genuine PNG with encrypted executable data added after its end marker.

The malware extracts that data and decrypts it using AES. A Go downloader then retrieves movinlike, a 64 MB Node.js information stealer packaged as a Windows executable.

This chain runs when the package is loaded, not through an install script. That distinction matters because disabling npm lifecycle scripts does not stop it.

Cyber Security News previously covered another npm attack hiding a RAT in PNG images, although that campaign stored payloads in image pixels rather than using MALFEX’s methods.

Remote Control, Account Theft, and Hidden Downloads

Overlord supports screen capture, keystroke logging, clipboard collection, file searches, remote commands, and a hidden desktop.

Its loader creates a scheduled task that runs every five minutes and carries a backdated 2020 start date. Checking only registry startup keys would miss this persistence method.

The RAT can obtain server addresses from encrypted Solana transaction memos. However, the analyzed sample had no configured Solana address or server list, and researchers saw no command-and-control traffic.

index[.]js (Source - Checkmarx)
index[.]js (Source – Checkmarx)

This is a supported capability, not proof that blockchain-based control was active in the tested infection. The movinlike stealer targets Discord tokens, browser cookies and saved passwords, Telegram sessions, and cryptocurrency wallets.

It changes Discord startup scripts, gathers account details, and sends stolen files to a Discord webhook in compressed chunks. Earlier reporting on StegaBin’s multistage credential theft shows why developer package installs deserve close security checks.

The third path hides a downloader inside an ASCII art package. A specific font value triggers the download, while long runs of spaces push malicious code beyond the visible editor window.

Download errors are silently ignored. Its latest analyzed payload was unavailable, and Checkmarx found no evidence connecting this separate downloader to movinlike.

Three malicious packages remained installable in Checkmarx’s October 1 snapshot. Two lacked malware advisories, while another advisory covered only two of four malicious versions.

Teams relying only on advisory feeds could therefore miss known bad code. These findings describe the report’s dated checks, not a fresh registry status check.

Developers should inspect dependency trees, lockfiles, package caches, and Windows endpoints. If an affected package was installed, isolate the host, preserve evidence, remove persistence, and change exposed passwords from a clean system.

End Telegram sessions and move exposed cryptocurrency funds to new wallets. Block all eight malicious packages and their specific download paths without blocking shared hosting services wholesale.

Removing packages alone does not undo stolen sessions or installed malware. Related coverage of fake npm install messages and compromised SAP npm packages reinforces the risk of trusting package setup activity.

Unit 42’s npm threat landscape analysis provides wider context for these supply-chain risks. Security teams should also review account activity and remove malicious copies from internal registries before developers reinstall affected dependencies.

Indicators of compromise (IoCs):-

Package Malicious versions
function-flag 1.7.3, 4.0.0, 3.0.0, 2.3.5–2.3.9
function-color 1.7.3, 1.0.0
cdn-img-fetch 1.0.0–1.0.3
img-to-native 1.0.0–1.0.3
native-runner 1.0.0–1.0.3
tlxbnhd 0.0.1
tldriver 0.0.1
mxdriver 0.0.1, 0.0.2

These version ranges are explicitly identified as malicious; Checkmarx states that [email protected] is not malicious.

URLs and Hosts

Source-listed indicator Role
hxxps[:]//api.imghippo.com/files/hOG8244hc.png Overlord loader served as PNG
www.image.com Second Overlord delivery domain associated with mxdriver
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png Stealer-chain image; used by cdn-img-fetch versions 1.0.0–1.0.2
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.jpg [email protected] payload
hxxp[:]//104.234.65.75:700/setup.exe movinlike download
hxxp[:]//104.234.65.75/setup.exe Alternate movinlike download path
hxxps[:]//cdnzona.discloud.app/node.exe [email protected] payload
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe [email protected] payload
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… [email protected]; incomplete in the source’s IoC table
hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe [email protected] payload
hxxps[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe [email protected] payload
hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe [email protected] payload
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe [email protected] payload
hxxps[:]//51.137.158.178/download [email protected] payload
discord.com/api/webhooks/1553545982975811594/… movinlike data-theft webhook; token omitted by the source

Checkmarx’s payload-version table uses hxxp[:] rather than hxxps[:] for the two 45.89.30.194 paths, the 191.96.81.101 path, and 51.137.158.178/download. Both protocol variants are therefore source-listed. The report also warns against blocking shared service domains wholesale; use the specific malicious paths.

SHA-256 Hashes

Artifact SHA-256
Overlord RAT loader served as PNG 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793
Signed AutoIt3.exe from archive 5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7
Encrypted Oxygen.a3x / h.a3x script fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67
Decoded Overlord RAT 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210
Current banner.png 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106
Stealer-chain downloader, September 25 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849
Stealer-chain downloader, September 25 e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4
Stealer-chain downloader, September 25 ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807
Stealer-chain downloader, September 26 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b
tlxbnhd/scripts/postinstall.js 7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e
movinlike c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437
[email protected]/index.js c7cf2323e4923428984297db7715d75fec5b964fe65c325b53e3fa360f3b8d86
[email protected]/index.js and version 1.0.1 430300450f5acbd69c29f02d8c2e243f7d1d6202d1826f6e4d7715f95c47299b
[email protected]/index.js 4cba0c785e66d517eabd0164f34a9c2d04549da93b5ee3eebdce5558daa2f47c
[email protected]/index.js 5c933aa533721fa293b284170dd4611a4d88f88cc89f2d9c28ea4e22305b1f75
[email protected] — banner.jpg 8f7ed69fb5505b57f06e673826779d459f7735739756de73a6d3347a9c8ea0cc
[email protected]/index.js d54853d6be467567d9f22d7f22ac48214df52c1f9c7a503930e901286423044a
[email protected]/example.js 886b84f83a0f760e664046ba40d8c800b7d0cf72190e13ca031ee5cf50f45bee

All hashes are reproduced as published. Checkmarx notes that movinlike can be rebuilt easily, so defenders should pair hash checks with file, task, and network evidence. The signed AutoIt interpreter is legitimate software; its hash alone does not establish infection outside this campaign context.

Host Artifacts and Persistence

Indicator Meaning
%LOCALAPPDATA%ScopeSmart Technologies Inc Overlord loader directory
%LOCALAPPDATA%ScopeSmart Technologies IncAutoIt3.exe Interpreter used by the loader
%LOCALAPPDATA%ScopeSmart Technologies Inch.a3x Encrypted AutoIt script
%LOCALAPPDATA%ScopeSmart Technologies IncSmartScope.vbs Associated script
Scheduled task Maiden Overlord persistence
Task command "AutoIt3.exe" "h.a3x" Scheduled execution
Task interval: every five minutes, no end time Persistence timing
Task start date: 1/1/2020 Backdated task metadata
Task author: Welcome; comment: Wichita Associated task metadata
<package dir>gldriver_pre_core.exe Dropped Overlord payload, deleted after launch
<package dir>gldriver_pre_asset.exe Dropped Overlord payload, deleted after launch
%APPDATA%MicrosoftWindowsnode_runtime_helper.exe Decrypted stealer-chain downloader
%TEMP%._cif_data Stealer-chain intermediate file
%APPDATA%node.exe [email protected] payload

These paths and task details are documented in the source’s host-artifact and persistence sections.

Supporting Attribution Indicators

Indicator Source context
malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4 npm publisher accounts
corpmalfex[@]gmail.com Payload repository Git author email
malfexteam2027 Stealer-chain AES decryption key
Murizada Owner name credited in the package README

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers appeared first on Cyber Security News.