Skip to content
THREATWIRE

Threats

MALFEX npm malware campaign delivers Overlord RAT and stealer

Checkmarx and CloudSEK tie eight malicious npm packages to one operator branded MALFEX. npm counts 40,767 lifetime downloads as of 1 October 2026, 37,419 of them for function-flag. Preinstall and postinstall scripts, plus code that runs on require, deliver Overlord RAT, the movinlike Node.js stealer, or a downloader to Windows hosts. function-flag, function-color and cdn-img-fetch were still installable on 7 October 2026.

High

Published 7 Oct 2026

On this page

What happened

Checkmarx Zero published research on 5 October 2026 describing MALFEX, an npm supply-chain malware campaign it links to a single operator active on the registry since 6 August 2023. CloudSEK had published its own analysis of the same operator on 30 September 2026, and The Hacker News summarised both on 7 October 2026. According to Checkmarx, the operator published twelve packages: eight malicious and four benign cover packages (function-ascii, malfapi, malfex-webhook-node and centralizemiddle).

The eight malicious packages are tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, cdn-img-fetch, function-flag and function-color. Checkmarx describes three independent delivery paths that do not share infrastructure. In the first, tlxbnhd, tldriver and mxdriver run obfuscated preinstall and postinstall scripts during npm install, fetch a Windows executable served as an image, and load Overlord RAT through an IExpress archive containing a signed AutoIt3 interpreter and an encrypted script. In the second, native-runner pulls in img-to-native, which requires cdn-img-fetch. These packages have no install hook and run when the package is loaded; they recover an encrypted Go downloader hidden after PNG image data, which then fetches movinlike, a 64 MB Node.js stealer packaged as a Windows executable. In the third, function-flag (and function-color, which only depends on it) carries a hidden download routine. In version 1.7.3 its postinstall script triggers that routine to download and run a node.exe file with a hidden window.

Who is affected

Checkmarx says only Windows systems are affected. The Overlord loader scripts contain launch commands for macOS and Linux, but the payload is a Windows executable. The function-flag routine depends on a Windows-only environment variable and fails silently elsewhere. The movinlike chain writes and fetches Windows executables. Developers, CI runners and build hosts on Windows that installed any of the eight names, directly or through function-color or native-runner, should be treated as exposed.

Checkmarx found no legitimate or widely used package depending on any operator package, so exposure is limited to systems that installed these names directly. It also reports no geographic or organizational targeting. CloudSEK attributes the operator to a Portuguese-speaking environment but says that is not evidence that the campaign targets Brazil.

What is confirmed

Checkmarx lists the malicious versions as function-flag 1.7.3 (latest), 4.0.0, 3.0.0 and 2.3.5 to 2.3.9; function-color 1.7.3 and 1.0.0; cdn-img-fetch, img-to-native and native-runner 1.0.0 to 1.0.3; tlxbnhd 0.0.1; tldriver 0.0.1; and mxdriver 0.0.1 and 0.0.2. The 40,767 figure is the sum of npm public lifetime download statistics for the eight packages as of 1 October 2026. function-flag accounts for 37,419 of them. Checkmarx stresses that these figures measure registry reach, not compromised hosts, and that some function-flag downloads come through function-color.

The MALFEX name comes from the operator's own branding. Checkmarx lists five npm publisher accounts (malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4), a git author email on the payload repository, a Portuguese README crediting the "Malfex team" and an owner named Murizada, and a stealer-chain key string built on the same name. Overlord is an open-source Go RAT with screen capture, keylogging, clipboard capture, window monitoring, file search, a remote shell and a hidden desktop. It can read encrypted C2 server lists from Solana transaction memos. Checkmarx says the build it analyzed had no Solana address configured and produced no C2 traffic in testing, while CloudSEK describes the resolver as wired in with live strings. movinlike injects into eight Discord clients to steal tokens, takes cookies and saved logins from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Yandex, copies Telegram Desktop session data and wallet data (for example MetaMask, Phantom and Coinbase Wallet), and exfiltrates to a Discord webhook that Checkmarx confirmed was live.

Overlord persistence uses a fake vendor folder named ScopeSmart Technologies Inc under the user's local AppData and a scheduled task named Maiden, backdated to 2020. Registry Run keys are not used. Other documented host artifacts are node_runtime_helper.exe under AppData Microsoft Windows and node.exe directly under AppData.

On npm, tlxbnhd, tldriver and mxdriver are unpublished, and img-to-native and native-runner are replaced by npm security holding packages. A ThreatWire check of the public npm registry on 7 October 2026 found function-flag (latest 1.7.3), function-color (latest 1.7.3) and cdn-img-fetch still installable. OSV has malware advisories for five removed packages (MAL-2026-16383, 16384, 16385, 17216 and 17218) and MAL-2026-17320 for cdn-img-fetch 1.0.0 and 1.0.1 only. OSV returned no advisory for function-flag or function-color.

Selected indicators published by Checkmarx (defanged; block specific paths on shared services, not whole domains):

  • api[.]imghippo[.]com (Overlord loader payload path), www[.]image[.]com (mxdriver delivery)
  • raw[.]githubusercontent[.]com/cavecrew/proj (stealer-chain image payload)
  • 104[.]234[.]65[.]75 (movinlike download server, port 700 and 80)
  • cdnzona[.]discloud[.]app (function-flag 1.7.3), apicdn[.]squareweb[.]app, bypasscdn[.]onrender[.]com, apizona[.]onrender[.]com, 45[.]89[.]30[.]194, 191[.]96[.]81[.]101, 51[.]137[.]158[.]178 (older function-flag versions)
  • SHA256 Overlord RAT (decoded): 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210
  • SHA256 Overlord loader served as PNG: 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793
  • SHA256 movinlike: c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437
  • SHA256 banner.png: 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106

Checkmarx's full table has further hashes for package files and stealer-chain downloaders.

What is not confirmed

The payload of function-flag 1.7.3 has not been recovered. Checkmarx says the download host was not responding and that nothing found so far links function-flag to movinlike. The download count does not establish how many machines were infected. Checkmarx established the Overlord process-hollowing step from code, not from runtime observation.

Sources differ on some counts and dates. CloudSEK's 30 September report counted five packages with advisories and three without. Checkmarx counted six with advisories after MAL-2026-17320 was published on 30 September. Both vendors say function-flag has been malicious since July 2025, matching the npm publish dates of 3.0.0 and 4.0.0 (18 July 2025) and 1.7.3 (4 August 2025). Checkmarx also lists versions 2.3.5 to 2.3.9, published in July and August 2024, as carrying payload URLs. The Hacker News wrote "July 2024" as the first publication date, which matches the package's creation (2.3.4, not malicious). npm metadata shows cdn-img-fetch 1.0.4, published late on 30 September 2026 (UTC), after the versions Checkmarx analyzed. ThreatWire has not seen a vendor verdict on 1.0.4. The Hacker News also mentions Overlord appearing in other 2026 campaigns; that is outside this report and not verified here.

What to do

Search every lockfile and install log (package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, yarn.lock) and the resolved dependency tree, including transitive dependencies, for all eight package names. Do not rely only on advisory-based scanners, which have no entry for function-flag, function-color or cdn-img-fetch 1.0.2 and later. Block all eight names at your registry proxy, including the wrappers, and purge cached copies from private registries and mirrors. A registry takedown does not remove copies already stored internally.

If any of these packages was installed on a Windows host, treat the host as compromised even if node_modules has been deleted. Isolate it, preserve evidence, and check for the ScopeSmart Technologies Inc folder, the Maiden scheduled task, node_runtime_helper.exe and node.exe under AppData. From a clean system, rotate Discord, browser-saved, npm, GitHub, cloud and CI credentials used on that host, end active Telegram sessions and move cryptocurrency to new wallets. Review proxy and DNS logs for the indicators above.

Disabling lifecycle scripts (npm's ignore-scripts option, or an allowlist in your package manager) stops the Overlord loaders and the function-flag postinstall. It does not stop the movinlike chain, which runs when the package is loaded, so keep it as one layer alongside name blocking and dependency review. When a malicious package is removed from the registry, also review its declared dependencies.

Sources: Checkmarx Zero, CloudSEK, The Hacker News, OSV (MAL-2026-16383, MAL-2026-16384, MAL-2026-16385, MAL-2026-17216, MAL-2026-17218, MAL-2026-17320), and the public npm registry.

Sources

Share on X@threatwire_https://www.threatwire.tech/threats/malfex-npm-malware-campaign-delivers-overlord-rat-and-stealer

More articles