MALFEX is an npm supply-chain malware campaign linked to what appears
to be a single adversary who has been publishing to the registry since
August 2023. As of this writing, the adversary has published twelve
packages, eight of them malicious. The attack delivers malware to
Windows systems through three separate paths: a loader for Overlord Remote Access Trojan (RAT)
(an open-source remote access trojan written in Go); a chain that
installs movinlike (a
Node.js stealer targeting Discord, browsers, Telegram, and
cryptocurrency wallets); and a long-running downloader hidden inside
function-flag.
As of 29 September 2026, three malicious packages remained live and
installable on npm: function-flag, function-color, and cdn-img-fetch. function-flag and function-color still have no
advisory, and the advisory published for cdn-img-fetch on September 30
covers only two of its four malicious versions. function-flag alone has been
malicious since July 2025 and accounts for 37,419 of the campaign’s
40,767 recorded downloads.
“MALFEX is an npm supply-chain malware campaign linked to what appears to be a single adversary who has been publishing to the registry since August 2023.”
TL;DR
- Campaign: MALFEX, a malicious package campaign run by a single operator on npm
- Operator activity: 6 August 2023 to present
- Packages: 12 tied to the operator; eight malicious and four benign cover packages
- Still installable (1 Oct 2026): function-flag, function-color, cdn-img-fetch
- Removed: tlxbnhd, tldriver, mxdriver (unpublished); img-to-native, native-runner (seized by npm)
- Downloads: 40,767 across the malicious packages, 3,017 in the past week (npm statistics, 1 October 2026)
- Execution: npm preinstall and postinstall scripts, and code that runs when a package is loaded
-
Payloads: Overlord RAT; the
movinlikestealer; an unrecoverednode.exefrom function-flag - Platform: Windows
- Advisories: Open Source Vulnerabilities (OSV) entries for the five removed packages, plus MAL-2026-17320 for cdn-img-fetch 1.0.0 and 1.0.1. None for function-flag, function-color, or cdn-img-fetch 1.0.2 and 1.0.3
- Immediate action: Block all eight malicious packages. If one was installed on Windows, isolate the host, remove persistence, and rotate exposed credentials from a clean system.
Severity and advisory status
Six of the eight malicious packages carry OSV malware advisories,
issued between 22 and 30 September 2026. Coverage is incomplete in two
ways. function-flag and
function-color have no
advisory at all, and the cdn-img-fetch advisory
(MAL-2026-17320, published 30 September) lists only versions 1.0.0 and
1.0.1, not the malicious 1.0.2 and 1.0.3. Tooling that relies only on
advisory feeds will miss them.
| Package | Advisory | Status (29 Sep 2026) |
|---|---|---|
tlxbnhd |
MAL-2026-16385 |
Unpublished |
tldriver |
MAL-2026-16384 |
Unpublished |
mxdriver |
MAL-2026-16383 |
Unpublished |
img-to-native |
MAL-2026-17216 |
Seized by npm |
native-runner |
MAL-2026-17218 |
Seized by npm |
function-flag |
None |
Live |
function-color |
None |
Live |
cdn-img-fetch |
MAL-2026-17320 (1.0.0 and
1.0.1 only) |
Live |
Table 1. Advisory coverage for the malicious MALFEX packages.
Affected packages and versions
| Package | Malicious versions | Role | Status (29 Sep 2026) |
|---|---|---|---|
function-flag |
1.7.3 (latest), 4.0.0, 3.0.0, 2.3.5–2.3.9 | Postinstall downloader | Live, no advisory |
function-color |
1.7.3, 1.0.0 | Wrapper for function-flag | Live, no advisory |
cdn-img-fetch |
1.0.0–1.0.3 | Stealer chain fetcher | Live, partial advisory |
img-to-native |
1.0.0–1.0.3 | Stealer chain decryptor | Seized by npm |
native-runner |
1.0.0–1.0.3 | Wrapper for img-to-native | Seized by npm |
tlxbnhd |
0.0.1 | Overlord RAT loader | Unpublished |
tldriver |
0.0.1 | Overlord RAT loader | Unpublished |
mxdriver |
0.0.1, 0.0.2 | Overlord RAT loader | Unpublished |
Table 2. Malicious packages attributed to the operator.
The operator also published four packages with no malicious code,
used as cover: function-ascii, malfapi, malfex-webhook-node, and centralizemiddle.
The operator signs their own work
The campaign is named after the operator’s own branding. The MALFEX
name appears across five npm publisher accounts (malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4), in the git author
email of the payload repository (corpmalfex[@]gmail.com), and in
the README of [email protected], which credits the
MALFEX team and names its owner as Murizada. The stealer chain’s
decryption key is the string malfexteam2027.
How the malware executes
The campaign uses three independent delivery paths. They appear to share a threat actor but do not share infrastructure, so blocking one pathway does not affect the others.
Path 1: Overlord RAT loaders: tlxbnhd, tldriver, mxdriver
- Windows executable served as
image/png - IExpress archive: signed AutoIt3.exe + encrypted Oxygen.a3x
- Overlord RAT
Each of the three packages works on its own. Obfuscated preinstall.js and postinstall.js scripts run during
every npm install, download
the payload from api.imghippo.com, save it as
gldriver_pre_core.exe and
gldriver_pre_asset.exe,
launch it, and then delete themselves. The scripts include launch
commands for macOS and Linux, but the payload is a Windows executable,
so only Windows systems are affected.
Although it is served as a PNG, the file is a Microsoft IExpress
self-extracting archive. It contains a legitimately signed AutoIt3
interpreter and an encrypted AutoIt script. The script decrypts its
embedded payload through several layers (XOR-encoded strings, RC4, and
LZNT1 compression) to produce Overlord RAT. Based on our analysis of the
script, it then injects Overlord into TapiUnattend.exe, a signed
Windows binary, using process hollowing with the parent process spoofed
as explorer.exe. We
established this step from the code rather than observing it at
runtime.

Path 2: Discord and browser stealer
native-runner → img-to-native → cdn-img-fetch
- banner.png from raw[.]githubusercontent[.]com/cavecrew/proj
- encrypted executable hidden after the PNG data
- Go downloader → movinlike (64 MB Node.js stealer)
None of these packages has an install hook. The malicious code runs
when the package is loaded: img-to-native requires cdn-img-fetch purely to trigger
it, and cdn-img-fetch
downloads banner.png as
soon as it is required. native-runner was a wrapper that
pulled in img-to-native.
img-to-native waits up
to 120 seconds for the image, locates data appended after the PNG end
marker, and decrypts it with the Advanced Encryption Standard (AES),
using the key malfexteam2027. The output is
written to %APPDATA%\Microsoft\Windows\node_runtime_helper.exe.
That Go executable downloads setup.exe from 104[.]234.65.75:700, which is
movinlike, a Node.js
stealer packaged as a Windows executable.

Path 3: function-flag downloader
function-color → function-flag
- postinstall: node example.js
- asciiArt(“oi”, “Bloody”)
- payload downloaded and executed (node.exe in 1.7.3)
function-flag is a
separate downloader and the longest-running part of the campaign. Each
malicious version carries a download routine in index.js, and each fetches its
payload from a different URL (Table 3). In 1.7.3, the current latest
version, the postinstall
script runs example.js,
which calls the package’s ASCII art function with the Bloody font. That
font value triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, a host on a
Brazilian application hosting service, saves it to %APPDATA%\node.exe, and runs it
with its window hidden.
Each malicious version of function-flag downloads its
payload from a different location:
| Version | Payload URL | Payload filename |
|---|---|---|
1.7.3 |
hxxps[:]//cdnzona.discloud.app/node.exe |
node.exe |
4.0.0 |
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe |
svchost.exe |
3.0.0 |
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/1395570372077682768/svchost.exe |
svchost.exe |
2.3.9 |
hxxp[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe |
nocry.exe |
2.3.8 |
hxxp[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe |
malfex.exe |
2.3.7 |
hxxp[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe |
malfex.exe |
2.3.6 |
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe |
malfex.exe |
2.3.5 |
hxxp[:]//51.137.158.178/download |
Not shown in URL |
Table 3. Payload URLs in each malicious version of function-flag. Version 2.3.4 is not malicious. The 3.0.0 URL is truncated in the available data.
The index.js of version
1.7.3 is shown below, with the space padding collapsed and the URL
defanged:

Two further details are visible in the code. The entire routine is
wrapped in an empty catch,
so if the download fails, as it does while the host is offline, the
install still completes without any error. And because process.env.APPDATA is undefined
outside Windows, the routine fails silently on macOS and Linux, which is
why only Windows systems are affected.
The malicious lines are padded with spaces so they sit past the visible edge of a typical code editor. And after publishing the malicious 4.0.0, the operator published a newer malicious build under the lower version number 1.7.3.
function-color contains
no payload of its own and installs function-flag as a dependency.
The 1.7.3 download host is not currently responding, so its payload has
not been recovered, and nothing we have found so far links function-flag to movinlike. The postinstall script
still runs on every install.
Persistence
For the Overlord RAT path, the loader copies itself into a fake vendor directory and registers a scheduled task:
%LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe
%LOCALAPPDATA%\ScopeSmart Technologies Inc\h.a3x
%LOCALAPPDATA%\ScopeSmart Technologies Inc\SmartScope.vbs
TaskName: \Maiden
Task To Run: "AutoIt3.exe" "h.a3x"
Repeat: every 5 minutes, no end time
Start Date: 1/1/2020 (backdated)
Author: Welcome
Comment: Wichita
ScopeSmart Technologies Inc is not a real company.
The task is backdated to 2020 so it does not appear among recently
created tasks. No registry Run keys are used, so a Run-key sweep will
miss this infection. SmartScope.vbs builds the string
"Wscript."+"Shell" by
concatenation to avoid scanners that search for CreateObject("Wscript.Shell").
Command and control and data theft
Overlord RAT reads its C2 from the Solana blockchain
Overlord has no hardcoded command and control (Command and Control (C2)) address. It can read encrypted memos that the operator posts in Solana transactions, decrypt them, and use the result as its server list. Changing servers only requires publishing a new transaction, so taking down a server does not disable the addressing scheme. The analyzed build had no Solana address or server list configured, and we observed no C2 traffic during testing.
Overlord focuses on monitoring and control rather than bulk credential theft. Its capabilities include screen capture, keylogging, clipboard capture, active window monitoring, file search, remote shell access, and a hidden desktop that uses a virtual display driver so the operator can work on the machine without the user seeing it.
movinlike exfiltrates to a Discord webhook
movinlike targets eight
Discord clients: Discord, Discord Canary, Discord PTB, Discord
Development, Lightcord, Vesktop, Nightcord, and Bluecord. It injects
code into the client’s startup scripts to steal authentication tokens,
then uses them to collect profile details, saved payment sources,
subscriptions, servers, friends, and linked accounts.
It also steals cookies and saved login data from Chrome, Edge, Brave,
Opera, Opera GX, Vivaldi, and Yandex; copies Telegram Desktop session
data from %APPDATA%\Telegram
Desktop\tdata; and collects data from cryptocurrency wallet
extensions such as MetaMask, Phantom, and Coinbase Wallet, as well as
desktop wallets. Everything is zipped, split into 25 MB chunks, and
posted to a hardcoded Discord webhook. We confirmed the webhook was
live; it was created on 26 September 2026 in a newly created Discord
server.
function-flag rotates its payload hosts
Each malicious version points to a different URL, with filenames
including node.exe, svchost.exe, nocry.exe, and malfex.exe. Several of the URLs
follow Discord’s attachment path format, and the 3.0.0 URL routes a
cdn[.]discordapp.com
attachment link through a proxy. The 1.7.3 host, cdnzona[.]discloud.app, is not
currently responding. The 1.7.3 postinstall script still attempts the
download on every install, and the host could start serving a payload
again at any time.
Impact and blast radius
npm recorded the following download counts for the malicious packages:
| Package | Lifetime downloads | Past week |
|---|---|---|
function-flag |
37,419 | 533 |
function-color |
300 | 2 |
cdn-img-fetch |
643 | 643 |
img-to-native |
967 | 967 |
native-runner |
872 | 872 |
tlxbnhd |
139 | 0 |
tldriver |
138 | 0 |
mxdriver |
289 | 0 |
| Total | 40,767 | 3,017 |
Table 4. Source: npm public download statistics, as of 1 October 2026.
These figures measure registry reach, not compromised hosts. Some
function-flag downloads
come through function-color, which installs it
as a dependency, and a download does not confirm the package was
installed on a Windows system.
No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target.
What is confirmed: eight packages with malicious
code were published to npm; three remained installable as of 29
September 2026, two of them with no advisory; and the payload
infrastructure was live when we checked, including the Overlord payload
URL, the GitHub payload, the setup.exe server, and the Discord
webhook.
Indicators of compromise
URLs and hosts
| Indicator | Role |
|---|---|
hxxps[:]//api.imghippo.com/files/hOG8244hc.png |
Overlord RAT payload, served as image/png |
www.image.com |
Second Overlord RAT delivery domain (mxdriver) |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png |
Stealer chain payload (PNG with appended data) |
hxxp[:]//104.234.65.75:700/setup.exe |
movinlike download |
hxxp[:]//104.234.65.75/setup.exe |
movinlike alternate path |
hxxps[:]//cdnzona.discloud.app/node.exe |
function-flag 1.7.3 payload |
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe |
function-flag 4.0.0 payload |
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… |
function-flag 3.0.0 payload |
hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe |
function-flag 2.3.9 payload |
hxxps[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe |
function-flag 2.3.8 payload |
hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe |
function-flag 2.3.7 payload |
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe |
function-flag 2.3.6 payload |
hxxps[:]//51.137.158.178/download |
function-flag 2.3.5 payload |
discord.com/api/webhooks/1553545982975811594/… |
movinlike exfiltration webhook |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.jpg |
cdn-img-fetch 1.0.3 payload |
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png |
cdn-img-fetch 1.0.0, 1.0.1, and 1.0.2 |
Table 5. api.imghippo.com, raw.githubusercontent.com, discord.com, and onrender.com are shared services; block the specific paths, not the domains.
File hashes (SHA256)
| Artifact | SHA256 |
|---|---|
| Overlord RAT loader (served as PNG) | 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793 |
| AutoIt3.exe (signed, from archive) | 5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7 |
| Oxygen.a3x / h.a3x (encrypted script) | fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67 |
| Overlord RAT (decoded) | 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210 |
| banner.png (current) | 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106 |
| Stealer chain downloader (25 Sep) | 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849 |
| Stealer chain downloader (25 Sep) | e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4 |
| Stealer chain downloader (25 Sep) | ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807 |
| Stealer chain downloader (26 Sep) | 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b |
| tlxbnhd/scripts/postinstall.js | 7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e |
| movinlike | c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437 |
| [email protected]/index.js | c7cf2323e4923428984297db7715d75fec5b964fe65c325b53e3fa360f3b8d86 |
| [email protected]/index.js (and 1.0.1) | 430300450f5acbd69c29f02d8c2e243f7d1d6202d1826f6e4d7715f95c47299b |
| [email protected]/index.js | 4cba0c785e66d517eabd0164f34a9c2d04549da93b5ee3eebdce5558daa2f47c |
| [email protected]/index.js | 5c933aa533721fa293b284170dd4611a4d88f88cc89f2d9c28ea4e22305b1f75 |
| [email protected] banner.jpg | 8f7ed69fb5505b57f06e673826779d459f7735739756de73a6d3347a9c8ea0cc |
| [email protected]/index.js | d54853d6be467567d9f22d7f22ac48214df52c1f9c7a503930e901286423044a |
| [email protected]/example.js | 886b84f83a0f760e664046ba40d8c800b7d0cf72190e13ca031ee5cf50f45bee |
Table 6. movinlike can be rebuilt easily, so pair hash matching with the behavioral indicators below.
Host artifacts
| Path or identifier | Meaning |
|---|---|
%LOCALAPPDATA%\ScopeSmart
Technologies Inc\ |
Overlord RAT loader install directory |
Scheduled task
\Maiden |
Overlord RAT persistence |
<package
dir>\gldriver_pre_core.exe |
Overlord RAT dropped payload (deleted after launch) |
<package
dir>\gldriver_pre_asset.exe |
Overlord RAT dropped payload (deleted after launch) |
%APPDATA%\Microsoft\Windows\node_runtime_helper.exe |
Stealer chain decrypted downloader |
%TEMP%\._cif_data |
Stealer chain intermediate file |
%APPDATA%\node.exe |
function-flag 1.7.3 payload |
Table 7. Host paths associated with the campaign.
How to detect exposure
Check the resolved dependency tree, including transitive dependencies:
npm ls function-flag function-color cdn-img-fetch img-to-native \
native-runner tlxbnhd tldriver mxdriver --all
Search lockfiles, since a malicious version can stay pinned after it is removed from the registry:
rg -n 'function-flag|function-color|cdn-img-fetch|img-to-native|native-runner|tlxbnhd|tldriver|mxdriver' \
package-lock.json npm-shrinkwrap.json pnpm-lock.yaml yarn.lock
On Windows hosts, check for the documented host artifacts in PowerShell:
Test-Path "$env:LOCALAPPDATA\ScopeSmart Technologies Inc"
Test-Path "$env:APPDATA\Microsoft\Windows\node_runtime_helper.exe"
Test-Path "$env:APPDATA\node.exe"
schtasks /query /tn "\Maiden" /fo LIST /v
Any True result or a
matching scheduled task should be treated as a likely infection. Also
review proxy and DNS logs for connections to the URLs and hosts in Table
5.
Remediation
If an affected package was installed on Windows
Treat the host as compromised, even if node_modules has since been
deleted.
- Isolate the host from the network and preserve logs and filesystem evidence for investigation.
- Delete the
\Maidenscheduled task and remove theScopeSmart Technologies Incdirectory,node_runtime_helper.exe, and%APPDATA%\node.exeif present, keeping a forensic copy. - From a known clean system, change passwords for Discord, accounts with credentials saved in the browser, and any other accounts used on the host. Terminate active Telegram sessions and move cryptocurrency funds to new wallets.
- Review Discord accounts for unexpected payment activity, and review other accounts for sign-in activity from unfamiliar locations.
- Purge the affected packages from private registries, proxies, and caches. A registry takedown does not remove copies already stored internally.
Block the campaign
- Block all eight malicious packages at your registry proxy,
including the wrappers. Blocking
function-flagalone does not stopfunction-color, and blockingimg-to-nativealone does not stopcdn-img-fetch. - Deny outbound traffic to the specific URLs in Table 5. Null-route
104.234.65.75, but do not blanket-block discord.com or raw.githubusercontent.com. - Do not rely on --ignore-scripts alone. It
stops the Overlord RAT loaders and
function-flag, but the stealer chain has no install hook and runs when the package is loaded. - When a package is removed from the registry, review its declared
dependencies too.
cdn-img-fetchstayed installable afterimg-to-native, the package that depends on it, was seized.
Incident timeline

Malicious Packages
Supply Chain Security