MALFEX: three npm packages still serving a RAT and stealer
A three-year npm campaign drops the Overlord RAT and the movinlike stealer. function-flag has 37,419 downloads and no advisory. How to check and clean up.
By Yaali. October 7, 2026, 6 min read, Supply chain, Threat intel, Windows.
A single operator calling themselves MALFEX has been publishing malicious packages to npm since August 2023. Checkmarx Zero counted 12 packages from five publisher accounts (malfexkkj, malfex_user, malfexteste2, malfexteste3 and malfexteste4). Eight of them are malicious and together have 40,767 downloads. Depending on the package, a Windows machine that installs or loads one ends up running the Overlord remote access trojan (RAT), a Node.js information stealer called movinlike, or an executable fetched by a hidden downloader.
Three of the malicious packages, function-flag, function-color and cdn-img-fetch, were still installable on September 29 according to Checkmarx, and they still were when we checked the npm registry on October 7. function-flag alone accounts for 37,419 downloads, has been malicious since July 18, 2025, and has no malware advisory, so a scanner that relies on advisory feeds will not flag it. If your developers or build agents run Windows and pull small utility packages from npm, check your lockfiles today.

How it works
npm lets a package declare lifecycle scripts such as preinstall and postinstall, which run automatically during npm install. A package can also run code at the top level of its index.js, which executes the moment another module calls require() on it. MALFEX uses both, and that difference decides which defences work.
Path 1, the Overlord loaders. tlxbnhd, tldriver and mxdriver ship obfuscated preinstall and postinstall scripts. According to the Amazon Inspector advisories, the scripts download https://api.imghippo.com/files/hOG8244hc.png from a public image host, save it as gldriver_pre_core.exe and gldriver_pre_asset.exe, launch it and delete the files. The "image" is a Microsoft IExpress self-extracting archive holding a legitimately signed AutoIt3 interpreter and an encrypted AutoIt script. The script unpacks through XOR, RC4 and LZNT1 compression into Overlord, an open source RAT written in Go, which Checkmarx says is injected into TapiUnattend.exe by process hollowing. The scripts carry launch commands for macOS and Linux, but the payload only runs on Windows.
Overlord captures the screen, logs keystrokes and the clipboard, watches the active window, searches files and gives the operator a remote shell. It has no hardcoded server address: it reads encrypted memos the operator posts in Solana blockchain transactions and uses the decrypted result as its server list, so blocking one IP does not cut it off.
Path 2, the stealer chain. native-runner pulls in img-to-native, which pulls in cdn-img-fetch. None of them uses an install hook. On require(), cdn-img-fetch downloads banner.png from the GitHub repository cavecrew/proj into a hidden temp file, ._cif_data. img-to-native finds data appended after the PNG end marker, decrypts it with AES and writes a Go downloader called node_runtime_helper.exe, which native-runner launches with a hidden window. The downloader fetches movinlike, a 64 MB Node.js bundle, from 104.234.65.75 on port 700.
movinlike injects into eight Discord clients (Discord, Canary, PTB, Development, Lightcord, Vesktop, Nightcord and Bluecord) to steal tokens. It takes saved credentials and cookies from seven browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Yandex), Telegram Desktop session data from tdata, and MetaMask, Phantom and Coinbase Wallet data. The haul is zipped and posted to a Discord webhook.
Path 3, the function-flag downloader. function-flag runs a postinstall.js that calls an ASCII-art function with a fixed trigger string, which starts a hidden download. Each of its eight malicious versions fetches from a different host, including 45.89.30.194, 191.96.81.101, 51.137.158.178, apizona.onrender.com, apicdn.squareweb.app and cdnzona.discloud.app, and saves files with names such as malfex.exe, svchost.exe, nocry.exe and node.exe. The code reads process.env.APPDATA, so it fails silently on macOS and Linux. function-color has no payload of its own and simply installs function-flag as a dependency.
What attackers are doing
The campaign has run from August 2023 to the present. The operator signs their work: the string malfexteam2027 appears in publisher names, README text and as the decryption key, and a README credits the "MALFEX team" with an owner named Murizada. CloudSEK links the payload repository to the GitHub account cavecrew, with commit times at UTC minus three hours and Portuguese text throughout. Checkmarx found no targeting of a particular sector or country, and no popular package depends on any of the operator's packages, so exposure comes from installing them directly.
The npm registry has replaced img-to-native and native-runner with security placeholders, and the three Overlord loaders were unpublished. That did not end the stealer chain, because cdn-img-fetch, the piece that fetches the encrypted payload from GitHub, remained live on npm. Its advisory, MAL-2026-17320, covers only versions 1.0.0 and 1.0.1 of the four malicious versions Checkmarx analysed. The registry now also lists a version 1.0.4 that neither report covers. npm's own statistics show 1,865 downloads of the three live packages in the week of September 28 to October 4, so installs are still happening, although an unknown share of those will be scanners and researchers.
What to do

Block the packages
Add all eight names to the deny list on your registry proxy or package firewall: function-flag, function-color, cdn-img-fetch, img-to-native, native-runner, tlxbnhd, tldriver and mxdriver. Block them by name, not only by advisory ID, because two have no advisory at all.
npm install --ignore-scripts stops paths 1 and 3, but not path 2, which runs on require(). Treat it as one layer. On the network side, deny api.imghippo.com/files/hOG8244hc.png, raw.githubusercontent.com/cavecrew/proj and the IP addresses above, and null-route 104.234.65.75. Checkmarx advises against blanket-blocking Discord or GitHub; block the specific URLs instead.
Check whether you pulled them
In each repository, run npm ls function-flag function-color cdn-img-fetch img-to-native native-runner tlxbnhd tldriver mxdriver --all, and search package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml and yarn.lock for the same names. Check build agents and developer laptops, not only the repositories, since a one-off install leaves no trace in a lockfile.
On Windows hosts, look for:
%LOCALAPPDATA%\ScopeSmart Technologies Inc\containingAutoIt3.exe,h.a3xandSmartScope.vbs.- A scheduled task
\Maiden, checked withschtasks /query /tn "\Maiden" /fo LIST /v, which relaunches the AutoIt script. node_runtime_helper.exeunder%APPDATA%\Microsoft\Windows\or%LOCALAPPDATA%\Programs\NodeRuntime\,%APPDATA%\node.exe, and._cif_datain%TEMP%.- In EDR,
TapiUnattend.exestarted withexplorer.exeas its parent, and outbound connections to the hosts listed above.
Checkmarx publishes SHA-256 hashes for the Overlord archive, the AutoIt interpreter, the decoded RAT and movinlike, along with the full webhook and download URLs, for loading into EDR and proxy blocklists.
Clean up a hit
Isolate the host, delete the \Maiden task and the ScopeSmart folder, and preferably rebuild, since Overlord gave the operator a shell. From a clean machine, change Discord passwords, every password saved in the browser and any other account used on the host, including npm, GitHub and cloud tokens. Terminate active Telegram sessions and move cryptocurrency to new wallets.
The lesson for dependency hygiene
Advisory feeds lagged this campaign by more than a year for its most downloaded package, and npm removed parent packages while leaving the dependency that carried the payload. A deny list keyed only on advisory IDs, or a review that stops when a package disappears, misses both. Review new dependencies on small, single-maintainer utility packages before they reach a lockfile.
Our red team code review covers dependency trees and build scripts, and security operations can hunt for the host indicators above across your fleet. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Checkmarx Zero, CloudSEK, SecurityWeek, Hackread, OSV MAL-2026-17320, OSV MAL-2026-17216, OSV MAL-2026-17218, OSV MAL-2026-16385, npm registry: function-flag.
Read next
- Kothamine RAT hides its commands inside Tailscale's tailcat
- 15,465 public MCP servers, and no vetting before you connect
- ClickFix hides its payload in the browser cache
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.