Threats & Adversaries · Supply Chain

MALFEX Malware Still Slips Past npm Cleanup

Checkmarx says the long-running MALFEX campaign has now pushed 12 npm packages and racked up more than 40,000 downloads since August 2023. Five malicious packages were removed, but three were still installable as of Oct. 1: function-flag, function-color, and cdn-img-fetch.

The campaign uses three delivery paths: one runs during npm install, one runs when the package is loaded, and one hides a downloader inside function-flag so the install can still appear to succeed if the payload fetch fails. That matters because function-flag has more than 37,000 downloads and no advisory flag, while Checkmarx says OSV coverage for cdn-img-fetch is incomplete and covers only two of its four malicious iterations.

For teams that rely on registry cleanup or advisory-based checks, the exposure does not end when a bad package is removed from npm. If malicious versions remain installable or only partly covered by advisories, they can still slip into CI systems and developer machines even after the ecosystem has started to react.

1 source · 7h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: MALFEX Malware Still Slips Past npm Cleanup

More from today