What is an npm supply-chain attack — one package ran 14 months without a warning
An npm supply-chain attack plants malicious code in a public JavaScript package so that it infects a developer's computer or build server the moment the package is installed. npm packages can declare install scripts such as 'postinstall' that run automatically during npm install, with no extra click. In the MALFEX campaign that security firm CloudSEK disclosed on September 30, 2026, a single operator uploaded at least 12 packages over three years starting in August 2023, and one of them, function-flag, stayed installable for about 14 months without any advisory. Eight packages flagged as malicious were downloaded 40,767 times in total
The three lines
- How — malware hides in a dependency; install scripts run automatically, so one npm install is enough
- MALFEX — one operator, 12+ packages over 3 years; one went 14 months unflagged; 40,767 downloads
- Defense — block install scripts, pin versions, delay new releases, never auto-accept dependencies
Key questions
- How to check if an npm package is malicious
- **Look at the name, history and install scripts before installing.** | Check | How | |---|---| | Name | One or two letters off a popular package? | | History | Publisher, creation date, downloads, repo link | | Scripts | preinstall/postinstall in package.json | | Advisories | npm audit, GHSA and MAL- advisories | | Block | npm install --ignore-scripts |
- Are npm postinstall scripts dangerous
- **They run the author's code with your user permissions the moment you install.** | Item | Detail | |---|---| | When | Automatically after npm install | | Permissions | The installing user's | | Abuse | Download executables, steal tokens and passwords | | Mitigation | ignore-scripts, allow-list only needed packages |
- MALFEX npm packages list
- **CloudSEK flagged three still-unadvised threats.** | Package | Status | |---|---| | function-flag | Malicious since July 18, 2025; ~14 months unflagged | | cdn-img-fetch | Installable after its parent was seized | | function-color | Pulls in function-flag | Already advised: tlxbnhd, tldriver, mxdriver, img-to-native and others.
Modern software is mostly other people's code. A supply-chain attack poisons that shared parts bin. Another case surfaced on npm, the largest JavaScript package registry. On September 30, 2026, security firm CloudSEK published its report on "MALFEX": one operator uploaded at least 12 packages over three years, and one stayed installable for about 14 months without any warning. Eight packages flagged as malicious were downloaded 40,767 times in total.
1. How it works: installing is enough
Developers add features with one line — npm install package-name. Each package can pull in dozens more, and packages can run code automatically during installation.
| Step | What happens |
|---|---|
| ① Upload | Attacker publishes a plausible package, or hijacks a popular maintainer account |
| ② Dependency | A normal-looking package pulls the malicious one in |
| ③ Install | Developer runs npm install |
| ④ Auto-run | preinstall/postinstall scripts execute with the user's permissions |
| ⑤ Infection | Remote-access trojan installed; tokens, passwords, browser data stolen |
| Type | Method | Example |
|---|---|---|
| Typosquatting | Names one or two characters off a popular package | 85 typosquats CloudSEK traced in September |
| Account or build hijack | Malicious versions of a real package | The Nx incident, August 2025 |
| Trojan tools | Useful function plus hidden payload | Some MALFEX packages |
2. MALFEX: what was new
| Item | Detail |
|---|---|
| Active | August 2023 – September 2026 |
| Operator | One actor using Portuguese-language accounts |
| Footprint | 12+ npm packages + 1 GitHub repo |
| Breakdown | 5 malicious with MAL- advisories, 3 malicious without, 4 benign cover tools |
| Downloads | 40,767 across eight flagged packages (The Hacker News) |
| Detection lag | function-flag malicious since July 18, 2025; ~14 months unflagged |
| Disclosure | Amazon Inspector advisories Sept 22–28; CloudSEK report Sept 30 |
| Chain | Behavior | Result |
|---|---|---|
| A | Install script downloads a Windows executable disguised as a PNG, unpacked via an AutoIt script | Open-source Overlord remote-access trojan |
| B | Encrypted payload in a PNG polyglot fetches a 64 MB Node.js program | Injects into Discord, steals browser data and Telegram sessions |
Two things stood out. First, CloudSEK found the first sample with a live command-and-control resolver hidden in Solana blockchain memos — block the server and the attacker simply writes a new address on-chain. Second, after npm seized the parent package img-to-native, its dependency cdn-img-fetch stayed installable. Remove one part, and the parts it pulled in can remain.
3. Where AI coding agents come in
Nothing shows MALFEX targeted AI tools. But the risk is growing: coding agents propose or run install commands themselves, and a developer who clicks "accept" without reading the name can let a typosquat in. In the August 2025 Nx incident, malicious install scripts reportedly invoked AI coding tools on developer machines with unsafe flags to hunt for sensitive files.
4. What developers and companies can do
| Measure | How | Effect |
|---|---|---|
| Block install scripts | npm install --ignore-scripts or npm config set ignore-scripts true | Stops auto-execution; allow-list exceptions |
| Pin versions | Commit package-lock.json, install with npm ci | No silent new versions |
| Delay | Wait a day or more before adopting new releases | Most malicious versions are reported within days |
| Check names | Watch for typos, new accounts, missing repo links | Typosquat defense |
| Audit | npm audit, dependency scanners, advisory feeds | Finds what already got in |
| AI agents | Require human approval for installs; disable auto-accept | Blocks agent-driven intake |
CloudSEK advises blocking function-flag, cdn-img-fetch and function-color; checking for an AutoIt executable in user app-data folders and a scheduled task named "\Maiden"; and blocking traffic to the payload hosts. For registries, it says takedowns should also inspect a package's declared dependencies.
5. Frequently asked
| Question | Answer |
|---|---|
| Are ordinary users at risk? | Directly, it's developer machines and build servers; infected builds can spread to users |
| Is this only npm? | No — PyPI, crates.io and other public registries face the same threat; npm is simply the largest |
| Does antivirus stop it? | Sometimes, but install scripts are run by legitimate tools; MALFEX went 14 months unflagged |
| Is it a CVE? | Malicious packages are intentional malware, tracked as MAL- advisories rather than scored vulnerabilities |
6. What remains unconfirmed
- Counts differ by method: 12+ packages (CloudSEK) versus eight malicious (The Hacker News).
- CloudSEK said the Discord exfiltration webhook was still live at publication; later status was not confirmed.
- No victims in specific countries, including Korea, were confirmed.
Sources
- CloudSEK — MALFEX: A malicious npm postinstall no advisory has caught for fourteen months
- The Hacker News — Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
- Hackread — MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
- AI Incident Database — Incident 1210: Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents
- npm Docs — scripts