Press Release Checkmarx Fusion: Hybrid Scanning Delivers the Most Complete Vulnerability Detection Available Read Now
Gartner® Checkmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security Get the Report
Outlook Report The Future of Application Security in the Era of AI Download Now
Latest Innovations
Checkmarx for Developers
Partners
Blog
Research

MALFEX npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work

The MALFEX campaign is a long-running npm supply-chain attack that delivers Remote Access Trojans (RAT), information stealers, or open Node.js processes as payloads. Learn about how the attack works, how to find out if you’re impacted, and what response actions to take.

Illustration of a cyber supply chain attack, showing npm packages, some with skulls, leading to a computer displaying a rat, data exfiltration icons, and a malicious executable download.

MALFEX is an npm supply-chain malware campaign linked to what appears to be a single adversary who has been publishing to the registry since August 2023. As of this writing, the adversary has published twelve packages, eight of them malicious. The attack delivers malware to Windows systems through three separate paths: a loader for Overlord Remote Access Trojan (RAT) (an open-source remote access trojan written in Go); a chain that installs movinlike (a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets); and a long-running downloader hidden inside function-flag.

As of 29 September 2026, three malicious packages remained live and installable on npm: function-flag, function-color, and cdn-img-fetch. function-flag and function-color still have no advisory, and the advisory published for cdn-img-fetch on September 30 covers only two of its four malicious versions. function-flag alone has been malicious since July 2025 and accounts for 37,419 of the campaign’s 40,767 recorded downloads.

“MALFEX is an npm supply-chain malware campaign linked to what appears to be a single adversary who has been publishing to the registry since August 2023.”

TL;DR

  • Campaign: MALFEX, a malicious package campaign run by a single operator on npm
  • Operator activity: 6 August 2023 to present
  • Packages: 12 tied to the operator; eight malicious and four benign cover packages
  • Still installable (1 Oct 2026): function-flag, function-color, cdn-img-fetch
  • Removed: tlxbnhd, tldriver, mxdriver (unpublished); img-to-native, native-runner (seized by npm)
  • Downloads: 40,767 across the malicious packages, 3,017 in the past week (npm statistics, 1 October 2026)
  • Execution: npm preinstall and postinstall scripts, and code that runs when a package is loaded
  • Payloads: Overlord RAT; the movinlike stealer; an unrecovered node.exe from function-flag
  • Platform: Windows
  • Advisories: Open Source Vulnerabilities (OSV) entries for the five removed packages, plus MAL-2026-17320 for cdn-img-fetch 1.0.0 and 1.0.1. None for function-flag, function-color, or cdn-img-fetch 1.0.2 and 1.0.3
  • Immediate action: Block all eight malicious packages. If one was installed on Windows, isolate the host, remove persistence, and rotate exposed credentials from a clean system.

Severity and advisory status

Six of the eight malicious packages carry OSV malware advisories, issued between 22 and 30 September 2026. Coverage is incomplete in two ways. function-flag and function-color have no advisory at all, and the cdn-img-fetch advisory (MAL-2026-17320, published 30 September) lists only versions 1.0.0 and 1.0.1, not the malicious 1.0.2 and 1.0.3. Tooling that relies only on advisory feeds will miss them.

Package Advisory Status (29 Sep 2026)
tlxbnhd MAL-2026-16385 Unpublished
tldriver MAL-2026-16384 Unpublished
mxdriver MAL-2026-16383 Unpublished
img-to-native MAL-2026-17216 Seized by npm
native-runner MAL-2026-17218 Seized by npm
function-flag None Live
function-color None Live
cdn-img-fetch MAL-2026-17320 (1.0.0 and 1.0.1 only) Live

Table 1. Advisory coverage for the malicious MALFEX packages.

Affected packages and versions

Package Malicious versions Role Status (29 Sep 2026)
function-flag 1.7.3 (latest), 4.0.0, 3.0.0, 2.3.5–2.3.9 Postinstall downloader Live, no advisory
function-color 1.7.3, 1.0.0 Wrapper for function-flag Live, no advisory
cdn-img-fetch 1.0.0–1.0.3 Stealer chain fetcher Live, partial advisory
img-to-native 1.0.0–1.0.3 Stealer chain decryptor Seized by npm
native-runner 1.0.0–1.0.3 Wrapper for img-to-native Seized by npm
tlxbnhd 0.0.1 Overlord RAT loader Unpublished
tldriver 0.0.1 Overlord RAT loader Unpublished
mxdriver 0.0.1, 0.0.2 Overlord RAT loader Unpublished

Table 2. Malicious packages attributed to the operator.

The operator also published four packages with no malicious code, used as cover: function-ascii, malfapi, malfex-webhook-node, and centralizemiddle.

The operator signs their own work

The campaign is named after the operator’s own branding. The MALFEX name appears across five npm publisher accounts (malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4), in the git author email of the payload repository (corpmalfex[@]gmail.com), and in the README of [email protected], which credits the MALFEX team and names its owner as Murizada. The stealer chain’s decryption key is the string malfexteam2027.

How the malware executes

The campaign uses three independent delivery paths. They appear to share a threat actor but do not share infrastructure, so blocking one pathway does not affect the others.

Path 1: Overlord RAT loaders: tlxbnhd, tldriver, mxdriver

  • Windows executable served as image/png
  • IExpress archive: signed AutoIt3.exe + encrypted Oxygen.a3x
  • Overlord RAT

Each of the three packages works on its own. Obfuscated preinstall.js and postinstall.js scripts run during every npm install, download the payload from api.imghippo.com, save it as gldriver_pre_core.exe and gldriver_pre_asset.exe, launch it, and then delete themselves. The scripts include launch commands for macOS and Linux, but the payload is a Windows executable, so only Windows systems are affected.

Although it is served as a PNG, the file is a Microsoft IExpress self-extracting archive. It contains a legitimately signed AutoIt3 interpreter and an encrypted AutoIt script. The script decrypts its embedded payload through several layers (XOR-encoded strings, RC4, and LZNT1 compression) to produce Overlord RAT. Based on our analysis of the script, it then injects Overlord into TapiUnattend.exe, a signed Windows binary, using process hollowing with the parent process spoofed as explorer.exe. We established this step from the code rather than observing it at runtime.

Screenshot of obfuscated JavaScript/Node.js code in a dark-themed editor, showing functions, variables, and control flow.
tlxbnhd/scripts/postinstall.js

Path 2: Discord and browser stealer

native-runner → img-to-native → cdn-img-fetch

  • banner.png from raw[.]githubusercontent[.]com/cavecrew/proj
  • encrypted executable hidden after the PNG data
  • Go downloader → movinlike (64 MB Node.js stealer)

None of these packages has an install hook. The malicious code runs when the package is loaded: img-to-native requires cdn-img-fetch purely to trigger it, and cdn-img-fetch downloads banner.png as soon as it is required. native-runner was a wrapper that pulled in img-to-native.

img-to-native waits up to 120 seconds for the image, locates data appended after the PNG end marker, and decrypts it with the Advanced Encryption Standard (AES), using the key malfexteam2027. The output is written to %APPDATA%\Microsoft\Windows\node_runtime_helper.exe. That Go executable downloads setup.exe from 104[.]234.65.75:700, which is movinlike, a Node.js stealer packaged as a Windows executable.

JavaScript code snippet showing functions to download and cache a remote image file from a URL.
cdn-img-fetch/index.js

Path 3: function-flag downloader

function-color → function-flag

  • postinstall: node example.js
  • asciiArt(“oi”, “Bloody”)
  • payload downloaded and executed (node.exe in 1.7.3)

function-flag is a separate downloader and the longest-running part of the campaign. Each malicious version carries a download routine in index.js, and each fetches its payload from a different URL (Table 3). In 1.7.3, the current latest version, the postinstall script runs example.js, which calls the package’s ASCII art function with the Bloody font. That font value triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, a host on a Brazilian application hosting service, saves it to %APPDATA%\node.exe, and runs it with its window hidden.

Each malicious version of function-flag downloads its payload from a different location:

Version Payload URL Payload filename
1.7.3 hxxps[:]//cdnzona.discloud.app/node.exe node.exe
4.0.0 hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe svchost.exe
3.0.0 hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/1395570372077682768/svchost.exe svchost.exe
2.3.9 hxxp[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe nocry.exe
2.3.8 hxxp[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe malfex.exe
2.3.7 hxxp[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe malfex.exe
2.3.6 hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe malfex.exe
2.3.5 hxxp[:]//51.137.158.178/download Not shown in URL

Table 3. Payload URLs in each malicious version of function-flag. Version 2.3.4 is not malicious. The 3.0.0 URL is truncated in the available data.

The index.js of version 1.7.3 is shown below, with the space padding collapsed and the URL defanged:

A screenshot of JavaScript code in a dark theme editor, showing module imports, an async function to download and execute a remote file, and a function to generate ASCII art.
function-flag/index.js

Two further details are visible in the code. The entire routine is wrapped in an empty catch, so if the download fails, as it does while the host is offline, the install still completes without any error. And because process.env.APPDATA is undefined outside Windows, the routine fails silently on macOS and Linux, which is why only Windows systems are affected.

The malicious lines are padded with spaces so they sit past the visible edge of a typical code editor. And after publishing the malicious 4.0.0, the operator published a newer malicious build under the lower version number 1.7.3.

function-color contains no payload of its own and installs function-flag as a dependency. The 1.7.3 download host is not currently responding, so its payload has not been recovered, and nothing we have found so far links function-flag to movinlike. The postinstall script still runs on every install.

Persistence

For the Overlord RAT path, the loader copies itself into a fake vendor directory and registers a scheduled task:

%LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe
%LOCALAPPDATA%\ScopeSmart Technologies Inc\h.a3x
%LOCALAPPDATA%\ScopeSmart Technologies Inc\SmartScope.vbs
 
TaskName:     \Maiden
Task To Run:  "AutoIt3.exe" "h.a3x"
Repeat:       every 5 minutes, no end time
Start Date:   1/1/2020  (backdated)
Author:       Welcome
Comment:      Wichita

ScopeSmart Technologies Inc is not a real company. The task is backdated to 2020 so it does not appear among recently created tasks. No registry Run keys are used, so a Run-key sweep will miss this infection. SmartScope.vbs builds the string "Wscript."+"Shell" by concatenation to avoid scanners that search for CreateObject("Wscript.Shell").

Command and control and data theft

Overlord RAT reads its C2 from the Solana blockchain

Overlord has no hardcoded command and control (Command and Control (C2)) address. It can read encrypted memos that the operator posts in Solana transactions, decrypt them, and use the result as its server list. Changing servers only requires publishing a new transaction, so taking down a server does not disable the addressing scheme. The analyzed build had no Solana address or server list configured, and we observed no C2 traffic during testing.

Overlord focuses on monitoring and control rather than bulk credential theft. Its capabilities include screen capture, keylogging, clipboard capture, active window monitoring, file search, remote shell access, and a hidden desktop that uses a virtual display driver so the operator can work on the machine without the user seeing it.

movinlike exfiltrates to a Discord webhook

movinlike targets eight Discord clients: Discord, Discord Canary, Discord PTB, Discord Development, Lightcord, Vesktop, Nightcord, and Bluecord. It injects code into the client’s startup scripts to steal authentication tokens, then uses them to collect profile details, saved payment sources, subscriptions, servers, friends, and linked accounts.

It also steals cookies and saved login data from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex; copies Telegram Desktop session data from %APPDATA%\Telegram Desktop\tdata; and collects data from cryptocurrency wallet extensions such as MetaMask, Phantom, and Coinbase Wallet, as well as desktop wallets. Everything is zipped, split into 25 MB chunks, and posted to a hardcoded Discord webhook. We confirmed the webhook was live; it was created on 26 September 2026 in a newly created Discord server.

function-flag rotates its payload hosts

Each malicious version points to a different URL, with filenames including node.exe, svchost.exe, nocry.exe, and malfex.exe. Several of the URLs follow Discord’s attachment path format, and the 3.0.0 URL routes a cdn[.]discordapp.com attachment link through a proxy. The 1.7.3 host, cdnzona[.]discloud.app, is not currently responding. The 1.7.3 postinstall script still attempts the download on every install, and the host could start serving a payload again at any time.

Impact and blast radius

npm recorded the following download counts for the malicious packages:

Package Lifetime downloads Past week
function-flag 37,419 533
function-color 300 2
cdn-img-fetch 643 643
img-to-native 967 967
native-runner 872 872
tlxbnhd 139 0
tldriver 138 0
mxdriver 289 0
Total 40,767 3,017

Table 4. Source: npm public download statistics, as of 1 October 2026.

These figures measure registry reach, not compromised hosts. Some function-flag downloads come through function-color, which installs it as a dependency, and a download does not confirm the package was installed on a Windows system.

No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target.

What is confirmed: eight packages with malicious code were published to npm; three remained installable as of 29 September 2026, two of them with no advisory; and the payload infrastructure was live when we checked, including the Overlord payload URL, the GitHub payload, the setup.exe server, and the Discord webhook.

Indicators of compromise

URLs and hosts

Indicator Role
hxxps[:]//api.imghippo.com/files/hOG8244hc.png Overlord RAT payload, served as image/png
www.image.com Second Overlord RAT delivery domain (mxdriver)
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png Stealer chain payload (PNG with appended data)
hxxp[:]//104.234.65.75:700/setup.exe movinlike download
hxxp[:]//104.234.65.75/setup.exe movinlike alternate path
hxxps[:]//cdnzona.discloud.app/node.exe function-flag 1.7.3 payload
hxxps[:]//apicdn.squareweb.app/attachments/1392577835742265576/1395570372077682768/svchost.exe function-flag 4.0.0 payload
hxxps[:]//bypasscdn.onrender.com/hxxps[:]//cdn[.]discordapp[.]com/attachments/1392577835742265576/139557037… function-flag 3.0.0 payload
hxxps[:]//45.89.30.194/attachments/1242231519943069778/1270557692171128915/nocry.exe function-flag 2.3.9 payload
hxxps[:]//45.89.30.194/attachments/1255944996503158885/1263421457598386237/malfex.exe function-flag 2.3.8 payload
hxxps[:]//191.96.81.101/attachments/1255944996503158885/1259416184265244682/malfex.exe function-flag 2.3.7 payload
hxxps[:]//apizona.onrender.com/attachments/1255944996503158885/1259416184265244682/malfex.exe function-flag 2.3.6 payload
hxxps[:]//51.137.158.178/download function-flag 2.3.5 payload
discord.com/api/webhooks/1553545982975811594/… movinlike exfiltration webhook
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.jpg cdn-img-fetch 1.0.3 payload
hxxps[:]//raw.githubusercontent.com/cavecrew/proj/main/banner.png cdn-img-fetch 1.0.0, 1.0.1, and 1.0.2

Table 5. api.imghippo.com, raw.githubusercontent.com, discord.com, and onrender.com are shared services; block the specific paths, not the domains.

File hashes (SHA256)

Artifact SHA256
Overlord RAT loader (served as PNG) 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793
AutoIt3.exe (signed, from archive) 5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7
Oxygen.a3x / h.a3x (encrypted script) fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67
Overlord RAT (decoded) 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210
banner.png (current) 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106
Stealer chain downloader (25 Sep) 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849
Stealer chain downloader (25 Sep) e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4
Stealer chain downloader (25 Sep) ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807
Stealer chain downloader (26 Sep) 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b
tlxbnhd/scripts/postinstall.js 7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e
movinlike c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437
[email protected]/index.js c7cf2323e4923428984297db7715d75fec5b964fe65c325b53e3fa360f3b8d86
[email protected]/index.js (and 1.0.1) 430300450f5acbd69c29f02d8c2e243f7d1d6202d1826f6e4d7715f95c47299b
[email protected]/index.js 4cba0c785e66d517eabd0164f34a9c2d04549da93b5ee3eebdce5558daa2f47c
[email protected]/index.js 5c933aa533721fa293b284170dd4611a4d88f88cc89f2d9c28ea4e22305b1f75
[email protected] banner.jpg 8f7ed69fb5505b57f06e673826779d459f7735739756de73a6d3347a9c8ea0cc
[email protected]/index.js d54853d6be467567d9f22d7f22ac48214df52c1f9c7a503930e901286423044a
[email protected]/example.js 886b84f83a0f760e664046ba40d8c800b7d0cf72190e13ca031ee5cf50f45bee

Table 6. movinlike can be rebuilt easily, so pair hash matching with the behavioral indicators below.

Host artifacts

Path or identifier Meaning
%LOCALAPPDATA%\ScopeSmart Technologies Inc\ Overlord RAT loader install directory
Scheduled task \Maiden Overlord RAT persistence
<package dir>\gldriver_pre_core.exe Overlord RAT dropped payload (deleted after launch)
<package dir>\gldriver_pre_asset.exe Overlord RAT dropped payload (deleted after launch)
%APPDATA%\Microsoft\Windows\node_runtime_helper.exe Stealer chain decrypted downloader
%TEMP%\._cif_data Stealer chain intermediate file
%APPDATA%\node.exe function-flag 1.7.3 payload

Table 7. Host paths associated with the campaign.

How to detect exposure

Check the resolved dependency tree, including transitive dependencies:

npm ls function-flag function-color cdn-img-fetch img-to-native \
  native-runner tlxbnhd tldriver mxdriver --all

Search lockfiles, since a malicious version can stay pinned after it is removed from the registry:

rg -n 'function-flag|function-color|cdn-img-fetch|img-to-native|native-runner|tlxbnhd|tldriver|mxdriver' \
  package-lock.json npm-shrinkwrap.json pnpm-lock.yaml yarn.lock

On Windows hosts, check for the documented host artifacts in PowerShell:

Test-Path "$env:LOCALAPPDATA\ScopeSmart Technologies Inc"
Test-Path "$env:APPDATA\Microsoft\Windows\node_runtime_helper.exe"
Test-Path "$env:APPDATA\node.exe"
schtasks /query /tn "\Maiden" /fo LIST /v

Any True result or a matching scheduled task should be treated as a likely infection. Also review proxy and DNS logs for connections to the URLs and hosts in Table 5.

Remediation

If an affected package was installed on Windows

Treat the host as compromised, even if node_modules has since been deleted.

  1. Isolate the host from the network and preserve logs and filesystem evidence for investigation.
  2. Delete the \Maiden scheduled task and remove the ScopeSmart Technologies Inc directory, node_runtime_helper.exe, and %APPDATA%\node.exe if present, keeping a forensic copy.
  3. From a known clean system, change passwords for Discord, accounts with credentials saved in the browser, and any other accounts used on the host. Terminate active Telegram sessions and move cryptocurrency funds to new wallets.
  4. Review Discord accounts for unexpected payment activity, and review other accounts for sign-in activity from unfamiliar locations.
  5. Purge the affected packages from private registries, proxies, and caches. A registry takedown does not remove copies already stored internally.

Block the campaign

  • Block all eight malicious packages at your registry proxy, including the wrappers. Blocking function-flag alone does not stop function-color, and blocking img-to-native alone does not stop cdn-img-fetch.
  • Deny outbound traffic to the specific URLs in Table 5. Null-route 104.234.65.75, but do not blanket-block discord.com or raw.githubusercontent.com.
  • Do not rely on --ignore-scripts alone. It stops the Overlord RAT loaders and function-flag, but the stealer chain has no install hook and runs when the package is loaded.
  • When a package is removed from the registry, review its declared dependencies too. cdn-img-fetch stayed installable after img-to-native, the package that depends on it, was seized.

Incident timeline

A timeline chart titled 'Malfex npm campaign' from August 2023 to October 2026. It shows the evolution of the campaign from initial benign package publishing, through malicious activity with packages like 'function-flag' and 'cdn-img-fetch', to registry actions and a final tally of over 40,000 malicious package downloads.
Campaign timeline. Registry state can change quickly; recheck package status and advisories before acting on this list.

Tags:

Malicious Packages

Supply Chain Security