Skip to content
TEN Brief Ten verified stories a day 2026.10.08 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 3 min read · Explainer

What is an npm supply-chain attack — one package ran 14 months without a warning

An npm supply-chain attack plants malicious code in a public JavaScript package so that it infects a developer's computer or build server the moment the package is installed. npm packages can declare install scripts such as 'postinstall' that run automatically during npm install, with no extra click. In the MALFEX campaign that security firm CloudSEK disclosed on September 30, 2026, a single operator uploaded at least 12 packages over three years starting in August 2023, and one of them, function-flag, stayed installable for about 14 months without any advisory. Eight packages flagged as malicious were downloaded 40,767 times in total

A developer seen from behind working at a laptop by a sunny window

The three lines

  • How — malware hides in a dependency; install scripts run automatically, so one npm install is enough
  • MALFEX — one operator, 12+ packages over 3 years; one went 14 months unflagged; 40,767 downloads
  • Defense — block install scripts, pin versions, delay new releases, never auto-accept dependencies

Key questions

How to check if an npm package is malicious
**Look at the name, history and install scripts before installing.** | Check | How | |---|---| | Name | One or two letters off a popular package? | | History | Publisher, creation date, downloads, repo link | | Scripts | preinstall/postinstall in package.json | | Advisories | npm audit, GHSA and MAL- advisories | | Block | npm install --ignore-scripts |
Are npm postinstall scripts dangerous
**They run the author's code with your user permissions the moment you install.** | Item | Detail | |---|---| | When | Automatically after npm install | | Permissions | The installing user's | | Abuse | Download executables, steal tokens and passwords | | Mitigation | ignore-scripts, allow-list only needed packages |
MALFEX npm packages list
**CloudSEK flagged three still-unadvised threats.** | Package | Status | |---|---| | function-flag | Malicious since July 18, 2025; ~14 months unflagged | | cdn-img-fetch | Installable after its parent was seized | | function-color | Pulls in function-flag | Already advised: tlxbnhd, tldriver, mxdriver, img-to-native and others.

Modern software is mostly other people's code. A supply-chain attack poisons that shared parts bin. Another case surfaced on npm, the largest JavaScript package registry. On September 30, 2026, security firm CloudSEK published its report on "MALFEX": one operator uploaded at least 12 packages over three years, and one stayed installable for about 14 months without any warning. Eight packages flagged as malicious were downloaded 40,767 times in total.

1. How it works: installing is enough

Developers add features with one line — npm install package-name. Each package can pull in dozens more, and packages can run code automatically during installation.

StepWhat happens
① UploadAttacker publishes a plausible package, or hijacks a popular maintainer account
② DependencyA normal-looking package pulls the malicious one in
③ InstallDeveloper runs npm install
④ Auto-runpreinstall/postinstall scripts execute with the user's permissions
⑤ InfectionRemote-access trojan installed; tokens, passwords, browser data stolen
TypeMethodExample
TyposquattingNames one or two characters off a popular package85 typosquats CloudSEK traced in September
Account or build hijackMalicious versions of a real packageThe Nx incident, August 2025
Trojan toolsUseful function plus hidden payloadSome MALFEX packages

2. MALFEX: what was new

ItemDetail
ActiveAugust 2023 – September 2026
OperatorOne actor using Portuguese-language accounts
Footprint12+ npm packages + 1 GitHub repo
Breakdown5 malicious with MAL- advisories, 3 malicious without, 4 benign cover tools
Downloads40,767 across eight flagged packages (The Hacker News)
Detection lagfunction-flag malicious since July 18, 2025; ~14 months unflagged
DisclosureAmazon Inspector advisories Sept 22–28; CloudSEK report Sept 30
ChainBehaviorResult
AInstall script downloads a Windows executable disguised as a PNG, unpacked via an AutoIt scriptOpen-source Overlord remote-access trojan
BEncrypted payload in a PNG polyglot fetches a 64 MB Node.js programInjects into Discord, steals browser data and Telegram sessions

Two things stood out. First, CloudSEK found the first sample with a live command-and-control resolver hidden in Solana blockchain memos — block the server and the attacker simply writes a new address on-chain. Second, after npm seized the parent package img-to-native, its dependency cdn-img-fetch stayed installable. Remove one part, and the parts it pulled in can remain.

3. Where AI coding agents come in

Nothing shows MALFEX targeted AI tools. But the risk is growing: coding agents propose or run install commands themselves, and a developer who clicks "accept" without reading the name can let a typosquat in. In the August 2025 Nx incident, malicious install scripts reportedly invoked AI coding tools on developer machines with unsafe flags to hunt for sensitive files.

4. What developers and companies can do

MeasureHowEffect
Block install scriptsnpm install --ignore-scripts or npm config set ignore-scripts trueStops auto-execution; allow-list exceptions
Pin versionsCommit package-lock.json, install with npm ciNo silent new versions
DelayWait a day or more before adopting new releasesMost malicious versions are reported within days
Check namesWatch for typos, new accounts, missing repo linksTyposquat defense
Auditnpm audit, dependency scanners, advisory feedsFinds what already got in
AI agentsRequire human approval for installs; disable auto-acceptBlocks agent-driven intake

CloudSEK advises blocking function-flag, cdn-img-fetch and function-color; checking for an AutoIt executable in user app-data folders and a scheduled task named "\Maiden"; and blocking traffic to the payload hosts. For registries, it says takedowns should also inspect a package's declared dependencies.

5. Frequently asked

QuestionAnswer
Are ordinary users at risk?Directly, it's developer machines and build servers; infected builds can spread to users
Is this only npm?No — PyPI, crates.io and other public registries face the same threat; npm is simply the largest
Does antivirus stop it?Sometimes, but install scripts are run by legitimate tools; MALFEX went 14 months unflagged
Is it a CVE?Malicious packages are intentional malware, tracked as MAL- advisories rather than scored vulnerabilities

6. What remains unconfirmed

  • Counts differ by method: 12+ packages (CloudSEK) versus eight malicious (The Hacker News).
  • CloudSEK said the Discord exfiltration webhook was still live at publication; later status was not confirmed.
  • No victims in specific countries, including Korea, were confirmed.

Sources

  1. CloudSEK — MALFEX: A malicious npm postinstall no advisory has caught for fourteen months
  2. The Hacker News — Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
  3. Hackread — MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
  4. AI Incident Database — Incident 1210: Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents
  5. npm Docs — scripts

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • Package counts differ: 12+ (CloudSEK) versus eight flagged as malicious (The Hacker News); 40,767 is the total for those eight.
  • No evidence ties MALFEX to AI coding agents; the AI-agent abuse case is the separate August 2025 Nx incident.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related