Full Report
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have
Analysis Summary
# Tool/Technique: MALFEX (npm Supply Chain Campaign)
## Overview
MALFEX is a long-running supply chain attack campaign targeting the npm ecosystem. It involves the distribution of malicious packages designed to infect Windows systems with information stealers and remote access trojans (RATs). The campaign relies on social engineering (npm package descriptions) and automated execution via npm lifecycle hooks.
## Technical Details
- **Type:** Malware Family / Supply Chain Attack
- **Platform:** Windows (Primary target), macOS (Related activity observed)
- **Capabilities:** Information theft (browsers, Discord, crypto wallets), remote access, and secondary payload delivery.
- **First Seen:** August 2023
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1195.001 - Supply Chain Compromise: Compromise Software Dependencies and Development Tools]
- **[TA0002 - Execution]**
- [T1204.002 - User Execution: Malicious File]
- [T1059.003 - Command and Scripting Interpreter: Windows Command Shell]
- [T1059.007 - Command and Scripting Interpreter: JavaScript]
- **[TA0005 - Defense Evasion]**
- [T1564.001 - Hide Artifacts: Hidden Window]
- **[TA0006 - Credential Access]**
- [T1555 - Credentials from Password Stores]
- **[TA0010 - Exfiltration]**
- [T1041 - Exfiltration Over C2 Channel]
- [T1567 - Exfiltration Over Web Service]
## Functionality
### Core Capabilities
- **Automated Execution:** Uses `postinstall` and other npm lifecycle hooks to trigger malicious JavaScript or shell commands immediately upon package installation.
- **Data Exfiltration:** The "movinlike" stealer targets sensitive data from Discord, Telegram, web browsers, and cryptocurrency wallet extensions.
- **Remote Access:** Deploys the **Overlord RAT**, an open-source Go-based trojan, allowing for full remote control of the compromised host.
### Advanced Features
- **Blockchain-based C2:** Overlord RAT utilizes Solana blockchain transactions to dynamically retrieve and extract the command-and-control (C2) server address, making the infrastructure harder to take down.
- **Hidden Execution:** Downloads a custom `node.exe` to `%APPDATA%` and executes it with a hidden window to remain persistent and stealthy.
- **Dependency Nesting:** Packages like `function-color` contain no malicious code themselves but list malicious packages (like `function-flag`) as dependencies to trigger the infection chain.
## Indicators of Compromise
- **File Names:**
- `node.exe` (located in `%APPDATA%`)
- `example.js`
- **npm Packages:**
- `tlxbnhd`
- `tldriver`
- `mxdriver`
- `img-to-native`
- `native-runner`
- `function-flag`
- `function-color`
- `cdn-img-fetch`
- **Network Indicators:**
- `cdnzona.discloud[.]app`
- Discord-based exfiltration hooks (standard for Node.js stealers)
- Solana blockchain transaction lookups
- **Behavioral Indicators:**
- Unexpected network connections initiated by `npm install` processes.
- Presence of non-standard `node.exe` binaries in user profile folders.
## Associated Threat Actors
- **Malfex Team / Murizada:** A Portuguese-speaking lone threat actor or small group likely based in Brazil (based on timezones, language in code, and hosting services used).
- **UNK_DeadDrop:** (Potential overlap) Tactical similarities observed in macOS variants, though attribution remains distinct.
## Detection Methods
- **Signature-based detection:** Scanning for the Overlord RAT Go binary and specific strings within the "movinlike" stealer.
- **Behavioral detection:** Monitoring for `npm` processes that spawn shell commands to download executables from cloud hosting services (e.g., Discloud, AWS, or Discord CDN).
- **Audit Logs:** Checking npm audit logs for the presence of the identified malicious package names.
## Mitigation Strategies
- **Dependency Pinning:** Use `package-lock.json` and verify checksums to ensure dependencies are not swapped for malicious versions.
- **Registry Security:** Use private npm registries or proxies that allow for the vetting of third-party packages.
- **Execution Policy:** Block lifecycle scripts during installation where possible using the `--ignore-scripts` flag: `npm install --ignore-scripts`.
- **Endpoint Protection:** Deploy EDR solutions to detect and block unauthorized executables running from `%APPDATA%`.
## Related Tools/Techniques
- **Overlord RAT:** An open-source Go-based RAT used in various global campaigns.
- **Typosquatting/Dependency Confusion:** General techniques used in supply chain attacks to trick developers into installing malicious code.
- **WP2Shell:** Exploitation framework for WordPress, observed delivering similar Overlord payloads.