movinlike is a Node.js information stealer packaged as an approximately 64 MB Windows executable. It is distributed through the MALFEX npm supply-chain campaign and targets Discord accounts, browser credentials and cookies, Telegram sessions, and cryptocurrency-wallet data. Its distribution exposes Windows developers and other users who load the malicious packages, without established geographic or industry-specific targeting.
The malware modifies startup code in eight Discord client variants: Discord, Discord Canary, Discord PTB, Discord Development, Lightcord, Vesktop, Nightcord, and Bluecord. It steals authentication tokens and collects account information, including profile details, saved payment sources, subscriptions, server memberships, friends, and linked accounts. It also extracts saved passwords and cookies from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex; copies Telegram Desktop session data; and collects data from browser-extension and desktop cryptocurrency wallets, including MetaMask, Phantom, and Coinbase Wallet. Stolen information is compressed, divided into 25 MB chunks, and exfiltrated through an attacker-controlled Discord webhook.
The delivery chain executes when malicious npm packages are loaded rather than through installation lifecycle hooks. It retrieves an image containing appended AES-encrypted executable data, decrypts that data into a Go downloader, and uses the downloader to retrieve movinlike. Consequently, disabling npm installation scripts alone does not prevent this delivery path. movinlike is associated with the MALFEX operation; remote-access and scheduled-task persistence features belonging to other MALFEX payloads are distinct from its documented functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Delivery Arm B decrypts an embedded payload and fetches a 64 MB Node.js bundle (movinlike) that injects into Discord clients, harvests browser and Telegram tdata, and exfiltrates stolen data to an active Discord webhook.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-targeting credential stealer distributed through the malicious npm packages img-to-native and cdn-img-fetch in the MALFEX campaign. Packaged as a 64 MB Node.js executable, it injects into Discord client variants, harvests browser credentials, steals Telegram session data, and targets cryptocurrency wallets. It exfiltrates stolen information through a Discord webhook.
Windows information stealer delivered through a malicious npm dependency chain in the MALFEX campaign. The chain extracts AES-encrypted executable data appended after a genuine PNG's end marker, then runs a Go downloader that retrieves movinlike. Execution occurs when the package is loaded, so disabling npm lifecycle scripts does not prevent this path. The stealer targets Discord tokens, browser cookies and saved passwords, Telegram sessions, and cryptocurrency wallets. It modifies Discord startup scripts, gathers account details, and exfiltrates stolen files to a Discord webhook in compressed chunks. Researchers found no evidence linking the campaign's separate ASCII-art-package downloader to movinlike.
Windows information stealer delivered through a MALFEX npm package chain that extracts AES-encrypted executable data appended to a genuine PNG. A decrypted Go downloader retrieves the stealer. The chain executes when the package is loaded, so disabling npm lifecycle scripts does not prevent this delivery path. movinlike steals Discord tokens, browser cookies and saved passwords, Telegram sessions, and cryptocurrency wallets. It modifies Discord startup scripts, gathers account information, and exfiltrates stolen files in compressed chunks through a Discord webhook. Researchers found no evidence connecting it to the campaign's separate ASCII-art-package downloader.
A Node.js information stealer that harvests sensitive data from Discord, browsers, Telegram, and cryptocurrency wallets. In the MALFEX npm supply-chain campaign, a delivery chain retrieves and executes a Go executable that subsequently fetches the stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.