Skip to content
Security & Trust

An npm malware campaign ran over three years; 3 packages still live Oct 8

Orca says the MALFEX campaign began in August 2023. One package went 14 months with no npm advisory.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
An npm malware campaign ran over three years; 3 packages still live Oct 8
In brief
  • Orca reports that a campaign active since August 2023 used eight npm packages, with 40,767 downloads combined, to install Windows malware. Three were still installable when Orca wrote.
  • The risk sits on the machine that ran the install, because that machine holds browser logins, tokens and wallet keys.
  • Search lockfiles for the eight names, check Windows build machines for the listed files, and rotate any credentials those machines could reach.

Download counts measure popularity, not exposure. The real exposure is the machine that ran the install. That machine often holds the keys to everything else. A campaign Orca Security described on October 8 shows how.

What Orca reported

Orca calls the campaign MALFEX. It says the campaign has been active since August 2023 and went undetected for over three years. CloudSEK and Checkmarx found it.

Orca links the campaign to a suspected lone actor, described as Brazilian. That person published 12 packages from five npm accounts. Eight were confirmed malicious in every version. Between them they drew 40,767 downloads.

Orca found that function-flag, function-color and cdn-img-fetch were still available on npm at the time of its report. The rest of the list is tlxbnhd, tldriver, mxdriver, img-to-native and native-runner.

40,767
Combined downloads of the eight malicious packages
Source: Orca Security research summary (October 8, 2026)

How the trick works

npm can run a script the moment a package is installed. This is called a postinstall script. Developers use it for normal setup work. Here, the scripts fetched malware instead.

Each malicious version pulled its payload from remote hosts that kept changing. Orca says this makes static detection difficult, because there is no fixed address to block.

Three kinds of malware were involved. The first is Overlord, a remote access tool written in Go. It came through tlxbnhd, tldriver and mxdriver. Its features include screen capture, keylogging, clipboard monitoring, file search, a remote shell and a hidden virtual desktop.

Overlord finds its controllers with a Solana blockchain lookup. Orca says this makes the attacker's infrastructure much harder to take down.

The second is "movinlike," a 64 MB Node.js program that steals credentials. It came through img-to-native and cdn-img-fetch. Orca says it injects into Discord clients, collects browser logins, takes Telegram session data and targets cryptocurrency wallets. It sends the loot out through a Discord webhook.

The third is a set of downloaders. In function-flag and function-color, the install script fetches Windows programs from changing hosts and runs them. Orca's summary does not link native-runner to a payload.

Why a small campaign still matters

Orca says none of the eight packages is a dependency of a major npm module. That limits the reach. A team is at risk only if someone installed one of them directly.

The payloads also work only on Windows. Orca says they fail silently on macOS and Linux. That is a real limit. But it still covers Windows developer laptops and Windows build servers. Those machines can hold browser sessions, tokens and signing keys.

37,419
Downloads of function-flag alone
Source: Orca Security research summary (October 8, 2026)

That one package drew most of the total. Orca dates its malicious behaviour to July 2025. In the 14 months since, it drew no npm advisory.

14
Months function-flag stayed malicious with no npm advisory
Source: Orca Security research summary (October 8, 2026)

The gap in the public record

Orca reports that Amazon Inspector issued OSV advisories for six of the eight packages. The dates run from September 22 to 28, 2026. OSV is an open database of known bad packages. Scanners use it to flag affected projects.

Orca's summary does not say which six packages are covered. So it cannot tell us how long any one of them lacked an OSV record. What it does show is simple. One package went 14 months without an npm advisory. OSV advisories for six packages appeared only in late September 2026.

Orca also sells scanning that uses these advisories. Weigh its product claims with that in mind. The timeline holds up on its own.

The lesson here is that a registry listing is not a security review. The useful question is not how popular a package is. It is who checks what the package does at install time.

What to ask your team

Start with the lockfiles. Orca advises searching every project for the eight names and removing any it finds. Then list the Windows machines that ran installs, build servers included.

Check those machines for the traces Orca lists. They are AutoIt3.exe in a LOCALAPPDATA folder named ScopeSmart Technologies Inc, node.exe in APPDATA, and node_runtime_helper.exe in APPDATA\Microsoft\Windows. Also look for a scheduled task named \Maiden, which Orca says runs every five minutes.

If a machine is affected, rotate every credential it could reach. Orca names Discord tokens, passwords saved in browsers, Telegram sessions and crypto wallet keys. Orca says a successful infection gives full remote access. Treat the machine as open to the attacker.

Two wider questions are worth asking. Does every project need install scripts to run on their own? And who reviews a new direct dependency before it reaches a build machine? Orca adds that Overlord has also turned up in campaigns exploiting WordPress flaws and in fake Zoom installers. This operator's tools are not limited to npm.

A package that runs code on install is a visitor with a key to the building. Decide who is allowed to hand out keys.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Orca Security.

Share this insight