NEWS

MALFEX npm Supply Chain Campaign Tops 40,000 Downloads After Three Years

Checkmarx traced MALFEX, a 3-year npm supply chain campaign spreading the Overlord RAT and Movinlike infostealer, to 8 packages with 40,767 downloads.

Dylan H.

News Desk

October 6, 2026
9 min read
MALFEX npm Supply Chain Campaign Tops 40,000 Downloads After Three Years

A Single Operator, Three Years, 40,000+ Downloads

Researchers at Checkmarx — corroborated independently by CloudSEK — have documented MALFEX, a long-running npm supply chain campaign that has been active since August 6, 2023 and has now accumulated more than 40,767 downloads across 8 malicious packages. The operator, who has published 12 packages total to the registry since the campaign began, mixes functioning utility code with malware loaders, delivering three distinct payloads: the Overlord remote access trojan (RAT), the Movinlike infostealer, and a dedicated downloader baked directly into the package function-flag. As of October 1, 2026, five of the eight malicious packages have been removed or seized by npm, but three remain live and installable — including function-flag, which alone accounts for 37,419 of the campaign's total downloads and reportedly carried a malicious payload for roughly 14 months before any public advisory covered it.


Campaign Details

AttributeValue
Campaign nameMALFEX
Discovered byCheckmarx (independently corroborated by CloudSEK)
Active sinceAugust 6, 2023
Packages published by operator12 total, 8 confirmed malicious
Total downloads (malicious packages)40,767
Platforms affectedWindows only — install logic fails silently on macOS/Linux
Payload typesOverlord RAT, Movinlike infostealer, embedded downloader
Attribution handlesTeam string malfexteam2027; GitHub account cavecrew
Registry accounts usedmalfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4
Status as of October 1, 20265 packages removed/unpublished; 3 still installable

The Eight Malicious Packages

PackageMalicious versionsDownloadsStatus
function-flag1.7.3, 4.0.0, 3.0.0, 2.3.5–2.3.937,419Live, no advisory
img-to-native1.0.0–1.0.3967Removed by npm
native-runner1.0.0–1.0.3872Removed by npm
cdn-img-fetch1.0.0–1.0.3643Live, advisory covers only 2 of 4 versions
mxdriver0.0.1, 0.0.2289Unpublished
function-color1.7.3, 1.0.0300Live, no advisory (wraps function-flag)
tlxbnhd0.0.1139Unpublished
tldriver0.0.1138Unpublished

How It Worked

Three Infection Paths From One Operator

Checkmarx's analysis found that MALFEX does not rely on a single technique — it runs three separate delivery chains, all traced back to the same adversary through shared infrastructure, a consistent attribution string, and reused code patterns.

The Overlord RAT Loader

Several packages ship obfuscated preinstall.js / postinstall.js lifecycle scripts that fire during npm install. These download a file disguised as a PNG image from a public image-hosting service (api.imghippo.com), which is actually a self-extracting archive containing a signed AutoIt3 interpreter and an encrypted script. Once assembled on disk, the loader launches the Overlord RAT — an open source remote access trojan written in Go — and then self-deletes to remove the installer artifact. Overlord gives the operator screen capture, keylogging, clipboard capture, active-window monitoring, remote shell access, file search, and a hidden virtual desktop for running tools without the victim noticing. Checkmarx notes Overlord has no hardcoded command-and-control address in this build; instead it reads encrypted memos the operator posts in Solana blockchain transactions, decrypts them, and uses the result as its live server list — a resilience technique that makes the C2 infrastructure difficult to take down by blocking a fixed IP or domain.

The Movinlike Infostealer Chain

A second chain skips install scripts entirely. Malicious code executes when the package is loaded or required by a consuming application, fetching a PNG polyglot file from a GitHub repository (raw.githubusercontent.com/cavecrew/proj) that has an encrypted executable appended after the image data. Decrypted with a hardcoded key tied to the string malfexteam2027, this drops Movinlike, a Node.js-based infostealer. Movinlike targets eight Discord client variants (Discord, Discord Canary, Discord PTB, Discord Development, Lightcord, Vesktop, Nightcord, and Bluecord) for authentication tokens, seven popular browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex) for saved credentials and cookies, Telegram Desktop session data, and cryptocurrency wallets including MetaMask, Phantom, and Coinbase Wallet. Stolen data is compressed, split into 25MB chunks, and exfiltrated to a hardcoded Discord webhook.

The function-flag Downloader (14 Months Undetected)

The longest-running and highest-volume component is a separate downloader embedded in every malicious version of function-flag. Each version fetches its payload from a different remote location, and the routine is deliberately written so that package installation completes successfully even if the payload download fails — avoiding the kind of visible install error that might tip off a developer or a CI pipeline. Checkmarx reports this downloader has been live inside function-flag since July 2025, carrying the bulk of the campaign's download count for roughly 14 months without a public security advisory flagging it.

Windows-Only by Design

Across all three chains, the infection logic is written to only function on Windows. On macOS and Linux, the same install scripts fail silently — no error, no payload, no indication anything was attempted. Combined with the lack of any geographic or organizational targeting, Checkmarx characterizes the campaign as opportunistic: anyone who installs one of the eight packages directly becomes a target, regardless of who they are or where they're building.

Impact Assessment

Impact AreaDescription
ConfidentialityBrowser-saved credentials and cookies, Discord authentication tokens, Telegram session data, and cryptocurrency wallet files exposed via Movinlike
System integrityOverlord RAT grants persistent remote shell access, keylogging, clipboard capture, and a hidden desktop on infected Windows hosts
Financial exposureTargeted wallets (MetaMask, Phantom, Coinbase Wallet) put developers' cryptocurrency holdings at direct risk of theft
Supply chain trust3 of 8 malicious packages remain installable on npm with incomplete or no public advisory as of this writing
Detection gapfunction-flag's downloader operated for roughly 14 months before any advisory was issued, despite accounting for 37,419 downloads
Blast radiusCheckmarx found no legitimate, widely used packages depend on any MALFEX package — exposure is limited to systems that installed one of the eight names directly

Recommendations

For Developers and Admins

  • Audit every repository, lockfile, and CI/build image for direct installs of the eight package names: function-flag, function-color, cdn-img-fetch, img-to-native, native-runner, tlxbnhd, tldriver, and mxdriver. On Windows, npm ls function-flag function-color cdn-img-fetch img-to-native native-runner tlxbnhd tldriver mxdriver --all will surface any direct or nested dependency.
  • Check infected-host indicators reported by Checkmarx: the directory %LOCALAPPDATA%\ScopeSmart Technologies Inc\, a scheduled task named \Maiden (schtasks /query /tn "\Maiden" /fo LIST /v), and dropped files such as %APPDATA%\node.exe or node_runtime_helper.exe under %APPDATA%\Microsoft\Windows\.
  • If any indicator is present, isolate the host's network access immediately. Uninstalling the npm package alone does not remove RAT persistence, dropped executables, or the scheduled task — those require separate manual or EDR-driven remediation.
  • Rotate every credential that could have been cached on the affected machine — browser-saved passwords, Discord session tokens, Telegram sessions, and any cryptocurrency wallet seed phrases or keystore files — and do it from a known-clean system, not the infected one.

For Security Teams

  • Block outbound traffic to the infrastructure identified in Checkmarx's report, including api.imghippo.com, raw.githubusercontent.com/cavecrew, and the IP 104.234.65.75:700, at the proxy or firewall level, and alert on any internal host reaching them.
  • Don't treat --ignore-scripts as a complete mitigation. The Movinlike chain in this campaign executes on module load/require(), not through an npm lifecycle hook, so install-script restrictions alone would not have stopped it.
  • Add all eight package names to internal registry proxy blocklists, and extend monitoring to catch future packages published under the same operator handles (malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4) or GitHub account (cavecrew).

For the Broader npm Ecosystem

  • Treat "no advisory yet" as "not yet reviewed" rather than "confirmed safe" — function-flag carried a live downloader for roughly 14 months before anyone flagged it publicly.
  • When a security advisory lands for one package in a related cluster, check whether sibling or wrapper packages were covered too. function-color wraps function-flag as a dependency and, per CloudSEK, remained installable even after related packages were taken down — a reminder that a partial takedown can leave active components reachable through a different package name.

Key Takeaways

  1. MALFEX has run since August 6, 2023 and has accumulated more than 40,767 downloads across 8 malicious npm packages tied to a single operator.
  2. The campaign delivers three distinct payloads: the Overlord RAT (full remote access via a Solana-based C2 resolver), the Movinlike infostealer (Discord, browsers, Telegram, crypto wallets), and a dedicated downloader embedded in function-flag.
  3. Infection is Windows-only by design — install logic fails silently on macOS and Linux, which likely contributed to the campaign evading broader detection for years.
  4. function-flag, the most-downloaded malicious package (37,419 downloads), reportedly carried its malicious downloader for roughly 14 months with no public security advisory.
  5. As of October 1, 2026, three of the eight packages — function-flag, function-color, and cdn-img-fetch — remain live and installable on npm with incomplete or no advisory coverage.
  6. Removing a flagged package is not sufficient on its own: RAT persistence, dropped executables, and scheduled tasks survive an npm uninstall, and related wrapper packages can keep a campaign's components reachable after a partial takedown.

Sources