A Single Operator, Three Years, 40,000+ Downloads
Researchers at Checkmarx — corroborated independently by CloudSEK — have documented MALFEX, a long-running npm supply chain campaign that has been active since August 6, 2023 and has now accumulated more than 40,767 downloads across 8 malicious packages. The operator, who has published 12 packages total to the registry since the campaign began, mixes functioning utility code with malware loaders, delivering three distinct payloads: the Overlord remote access trojan (RAT), the Movinlike infostealer, and a dedicated downloader baked directly into the package function-flag. As of October 1, 2026, five of the eight malicious packages have been removed or seized by npm, but three remain live and installable — including function-flag, which alone accounts for 37,419 of the campaign's total downloads and reportedly carried a malicious payload for roughly 14 months before any public advisory covered it.
Campaign Details
| Attribute | Value |
|---|---|
| Campaign name | MALFEX |
| Discovered by | Checkmarx (independently corroborated by CloudSEK) |
| Active since | August 6, 2023 |
| Packages published by operator | 12 total, 8 confirmed malicious |
| Total downloads (malicious packages) | 40,767 |
| Platforms affected | Windows only — install logic fails silently on macOS/Linux |
| Payload types | Overlord RAT, Movinlike infostealer, embedded downloader |
| Attribution handles | Team string malfexteam2027; GitHub account cavecrew |
| Registry accounts used | malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4 |
| Status as of October 1, 2026 | 5 packages removed/unpublished; 3 still installable |
The Eight Malicious Packages
| Package | Malicious versions | Downloads | Status |
|---|---|---|---|
function-flag | 1.7.3, 4.0.0, 3.0.0, 2.3.5–2.3.9 | 37,419 | Live, no advisory |
img-to-native | 1.0.0–1.0.3 | 967 | Removed by npm |
native-runner | 1.0.0–1.0.3 | 872 | Removed by npm |
cdn-img-fetch | 1.0.0–1.0.3 | 643 | Live, advisory covers only 2 of 4 versions |
mxdriver | 0.0.1, 0.0.2 | 289 | Unpublished |
function-color | 1.7.3, 1.0.0 | 300 | Live, no advisory (wraps function-flag) |
tlxbnhd | 0.0.1 | 139 | Unpublished |
tldriver | 0.0.1 | 138 | Unpublished |
How It Worked
Three Infection Paths From One Operator
Checkmarx's analysis found that MALFEX does not rely on a single technique — it runs three separate delivery chains, all traced back to the same adversary through shared infrastructure, a consistent attribution string, and reused code patterns.
The Overlord RAT Loader
Several packages ship obfuscated preinstall.js / postinstall.js lifecycle scripts that fire during npm install. These download a file disguised as a PNG image from a public image-hosting service (api.imghippo.com), which is actually a self-extracting archive containing a signed AutoIt3 interpreter and an encrypted script. Once assembled on disk, the loader launches the Overlord RAT — an open source remote access trojan written in Go — and then self-deletes to remove the installer artifact. Overlord gives the operator screen capture, keylogging, clipboard capture, active-window monitoring, remote shell access, file search, and a hidden virtual desktop for running tools without the victim noticing. Checkmarx notes Overlord has no hardcoded command-and-control address in this build; instead it reads encrypted memos the operator posts in Solana blockchain transactions, decrypts them, and uses the result as its live server list — a resilience technique that makes the C2 infrastructure difficult to take down by blocking a fixed IP or domain.
The Movinlike Infostealer Chain
A second chain skips install scripts entirely. Malicious code executes when the package is loaded or required by a consuming application, fetching a PNG polyglot file from a GitHub repository (raw.githubusercontent.com/cavecrew/proj) that has an encrypted executable appended after the image data. Decrypted with a hardcoded key tied to the string malfexteam2027, this drops Movinlike, a Node.js-based infostealer. Movinlike targets eight Discord client variants (Discord, Discord Canary, Discord PTB, Discord Development, Lightcord, Vesktop, Nightcord, and Bluecord) for authentication tokens, seven popular browsers (Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex) for saved credentials and cookies, Telegram Desktop session data, and cryptocurrency wallets including MetaMask, Phantom, and Coinbase Wallet. Stolen data is compressed, split into 25MB chunks, and exfiltrated to a hardcoded Discord webhook.
The function-flag Downloader (14 Months Undetected)
The longest-running and highest-volume component is a separate downloader embedded in every malicious version of function-flag. Each version fetches its payload from a different remote location, and the routine is deliberately written so that package installation completes successfully even if the payload download fails — avoiding the kind of visible install error that might tip off a developer or a CI pipeline. Checkmarx reports this downloader has been live inside function-flag since July 2025, carrying the bulk of the campaign's download count for roughly 14 months without a public security advisory flagging it.
Windows-Only by Design
Across all three chains, the infection logic is written to only function on Windows. On macOS and Linux, the same install scripts fail silently — no error, no payload, no indication anything was attempted. Combined with the lack of any geographic or organizational targeting, Checkmarx characterizes the campaign as opportunistic: anyone who installs one of the eight packages directly becomes a target, regardless of who they are or where they're building.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Browser-saved credentials and cookies, Discord authentication tokens, Telegram session data, and cryptocurrency wallet files exposed via Movinlike |
| System integrity | Overlord RAT grants persistent remote shell access, keylogging, clipboard capture, and a hidden desktop on infected Windows hosts |
| Financial exposure | Targeted wallets (MetaMask, Phantom, Coinbase Wallet) put developers' cryptocurrency holdings at direct risk of theft |
| Supply chain trust | 3 of 8 malicious packages remain installable on npm with incomplete or no public advisory as of this writing |
| Detection gap | function-flag's downloader operated for roughly 14 months before any advisory was issued, despite accounting for 37,419 downloads |
| Blast radius | Checkmarx found no legitimate, widely used packages depend on any MALFEX package — exposure is limited to systems that installed one of the eight names directly |
Recommendations
For Developers and Admins
- Audit every repository, lockfile, and CI/build image for direct installs of the eight package names:
function-flag,function-color,cdn-img-fetch,img-to-native,native-runner,tlxbnhd,tldriver, andmxdriver. On Windows,npm ls function-flag function-color cdn-img-fetch img-to-native native-runner tlxbnhd tldriver mxdriver --allwill surface any direct or nested dependency. - Check infected-host indicators reported by Checkmarx: the directory
%LOCALAPPDATA%\ScopeSmart Technologies Inc\, a scheduled task named\Maiden(schtasks /query /tn "\Maiden" /fo LIST /v), and dropped files such as%APPDATA%\node.exeornode_runtime_helper.exeunder%APPDATA%\Microsoft\Windows\. - If any indicator is present, isolate the host's network access immediately. Uninstalling the npm package alone does not remove RAT persistence, dropped executables, or the scheduled task — those require separate manual or EDR-driven remediation.
- Rotate every credential that could have been cached on the affected machine — browser-saved passwords, Discord session tokens, Telegram sessions, and any cryptocurrency wallet seed phrases or keystore files — and do it from a known-clean system, not the infected one.
For Security Teams
- Block outbound traffic to the infrastructure identified in Checkmarx's report, including
api.imghippo.com,raw.githubusercontent.com/cavecrew, and the IP104.234.65.75:700, at the proxy or firewall level, and alert on any internal host reaching them. - Don't treat
--ignore-scriptsas a complete mitigation. The Movinlike chain in this campaign executes on module load/require(), not through an npm lifecycle hook, so install-script restrictions alone would not have stopped it. - Add all eight package names to internal registry proxy blocklists, and extend monitoring to catch future packages published under the same operator handles (
malfexkkj,malfex_user,malfexteste2,malfexteste3,malfexteste4) or GitHub account (cavecrew).
For the Broader npm Ecosystem
- Treat "no advisory yet" as "not yet reviewed" rather than "confirmed safe" —
function-flagcarried a live downloader for roughly 14 months before anyone flagged it publicly. - When a security advisory lands for one package in a related cluster, check whether sibling or wrapper packages were covered too.
function-colorwrapsfunction-flagas a dependency and, per CloudSEK, remained installable even after related packages were taken down — a reminder that a partial takedown can leave active components reachable through a different package name.
Key Takeaways
- MALFEX has run since August 6, 2023 and has accumulated more than 40,767 downloads across 8 malicious npm packages tied to a single operator.
- The campaign delivers three distinct payloads: the Overlord RAT (full remote access via a Solana-based C2 resolver), the Movinlike infostealer (Discord, browsers, Telegram, crypto wallets), and a dedicated downloader embedded in
function-flag. - Infection is Windows-only by design — install logic fails silently on macOS and Linux, which likely contributed to the campaign evading broader detection for years.
function-flag, the most-downloaded malicious package (37,419 downloads), reportedly carried its malicious downloader for roughly 14 months with no public security advisory.- As of October 1, 2026, three of the eight packages —
function-flag,function-color, andcdn-img-fetch— remain live and installable on npm with incomplete or no advisory coverage. - Removing a flagged package is not sufficient on its own: RAT persistence, dropped executables, and scheduled tasks survive an
npm uninstall, and related wrapper packages can keep a campaign's components reachable after a partial takedown.