Breaking
Cyber CrimeDeveloping Story

MALFEX npm Campaign Hidden in Eight Packages

CloudSEK and Checkmarx say a lone actor shipped 12 npm packages since 2023, eight flagged malicious and downloaded 40,767 times.

··3 hours ago·6 min read
a computer screen with a bunch of code on it
Photo by Chris Ried on Unsplash

Eight npm packages tied to a supply chain malware campaign have been downloaded 40,767 times in total, according to research disclosed by CloudSEK and Checkmarx. The campaign, codenamed MALFEX, is assessed to be the work of a lone threat actor who has published 12 packages since August 2023, with eight flagged as malicious. The packages are designed to infect Windows systems through three separate pathways, and some remain live.

The findings describe a long-running operation that pushes information stealers and remote access trojans onto compromised hosts. According to Checkmarx, one of the packages still available, function-flag, carries a postinstall hook that runs a JavaScript payload to download code from a remote server.

Three Infection Routes

The campaign is built around three distinct mechanisms. The first is a loader for Overlord, an open-source RAT written in Go that uses Solana transactions to extract its command-and-control (C2) address. The second is a chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets. The third is a downloader.

The packages identified by the researchers are tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch.

Of the total downloads, 37,419 correspond to function-flag, making it the largest driver of the activity, the researchers said. That package was first published in July 2024, and its latest version was released on August 4, 2025.

Three packages — tlxbnhd, tldriver, and mxdriver — act as Overlord RAT loaders, with malicious code triggered via lifecycle hooks to download and run a Windows executable. A second subset, including img-to-native, requires cdn-img-fetch to retrieve and execute a Go executable, which then fetches a Node.js stealer capable of harvesting sensitive data.

Hidden Trigger in a Display Function

Within function-flag, a postinstall hook runs a JavaScript payload to download a payload from a remote server. Each version of the package has been found to serve a payload from a different location.

The function-color package embeds no payload of its own, but lists function-flag as a dependency. Checkmarx described how the current release behaves, naming the specific host used for the download.

"In 1.7.3, the current latest version, the postinstall script runs example.js, which calls the package's ASCII art function with the Bloody font," Checkmarx said. "That font value triggers a hidden routine that downloads node.exe from cdnzona.discloud.app, a host on a Brazilian application hosting service, saves it to %APPDATA%\node.exe, and runs it with its window hidden."

— Checkmarx, in its analysis of the MALFEX campaign.

The download host is described as sitting on a Brazilian application hosting service. The executable is saved to the Windows %APPDATA% directory and launched with its window hidden, according to the researchers.

Where the Operator Traces Back To

CloudSEK pointed to a set of linguistic and repository clues that it said point to the operator's own space. The research firm was explicit that these markers describe the actor, not the targets.

"The operator is Portuguese-speaking, the git commits sit at -0300, one repository description is in Portuguese, and the GitHub display name and email give a common Brazilian handle," CloudSEK said. "None of this is an argument that the campaign targets Brazil. It is a piece of attribution to the operator's own linguistic space and nothing more. The delivery is npm and Discord, both of which are global; the second-stage targeting is opportunistic."

— CloudSEK, in its writeup of the campaign.

The npm project description also carries a welcome message written in Portuguese, stating: "This project was created with a lot of love and dedication by the Malfex team, whose owner is Murizada."

According to the researchers, the campaign uses npm and Discord for delivery, both of which are global platforms. The second stage is described as opportunistic rather than targeted at any particular region.

Overlord's Wider Footprint

Overlord RAT has been observed in two other campaigns since July 2026, according to the source material. One involved the exploitation of WordPress flaws tracked as CVE-2026-63030 and CVE-2026-60137, also known as wp2shell. The other was a macOS campaign in which a fake Zoom installer is used to deploy the RAT.

The fake Zoom installer campaign shares tactical overlaps with a suspected North Korea-aligned threat cluster dubbed UNK_DeadDrop, according to the source. The researchers did not state that the MALFEX operator is connected to that cluster.

The Overlord RAT itself is open source and written in Go, with the C2 address extracted through Solana transactions. Its appearance across WordPress exploitation and a macOS fake installer shows it surfacing in different operations.

The Packages and Their Numbers

  • 40,767 — total downloads across the eight malicious packages
  • 37,419 — downloads attributed to function-flag, the largest driver
  • 12 — packages published by the operator since August 2023
  • 8 — packages flagged as malicious
  • July 2024 — when function-flag was first published
  • August 4, 2025 — release date of the latest function-flag version
  • CVE-2026-63030 and CVE-2026-60137 — WordPress flaws tied to a separate Overlord campaign

The packages that researchers said remain live are function-flag, function-color, and cdn-img-fetch. The full list of flagged packages is tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch.

How the Payload Chain Fits Together

The structure described by the researchers separates the campaign into roles. The Overlord loaders — tlxbnhd, tldriver, and mxdriver — use lifecycle hooks to pull down and run a Windows executable. The img-to-native package depends on cdn-img-fetch to retrieve and execute a Go binary, which in turn fetches a Node.js stealer.

The Node.js stealer, movinlike, targets Discord, browsers, Telegram, and cryptocurrency wallets, according to the source. The downloader pathway is the third route the researchers identified.

Function-flag carries the postinstall hook that runs the JavaScript payload. Across versions, that payload has been served from different locations, the researchers found. Function-color carries no payload itself but pulls function-flag in as a dependency.

The version details matter for anyone trying to match a local install against the report. Checkmarx named 1.7.3 as the current latest version of function-flag, the one whose postinstall script runs example.js and triggers the download of node.exe to %APPDATA%.

What the Researchers Say to Do

The researchers identified three pathways and eight packages, and the practical starting point is inventory: projects should be checked for the named packages. The packages were published to npm, a public registry, and the delivery described by the researchers runs through npm and Discord.

The source material does not include a vendor removal timeline, takedown confirmation, or a count of affected organizations. What it does provide is the package list, the download totals, the version dates, and the technical description of how each package behaves when installed. Those are the concrete facts available for defenders trying to determine whether their environment pulled in any of the flagged code.

CloudSEK and Checkmarx have both published their findings. CloudSEK's writeup is available on its blog, and the campaign is assessed as the work of a single operator rather than a larger group.

Why This Matters for Build Pipelines

The MALFEX campaign is a reminder that supply chain risk does not announce itself. A single package with 37,419 downloads can seed infections across development environments without any obvious signal to the developer installing it, and the resulting credential theft may not surface quickly. The Overlord RAT's use of Solana transactions for C2 resolution suggests that even when a campaign is identified, disrupting its infrastructure may be harder than with a fixed domain. For teams that build with npm, the eight named packages are a concrete list to check against — and the fact that three of them were still live at the time of the research suggests the exposure window may still be open.

#npm#supply chain#malware#overlord rat#infostealer#windows

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories