MALFEX npm malware ran undetected for 14 months
MALFEX, a one-person npm malware campaign, published 12 packages since 2023 and drew 40,767 downloads. Some packages are still live with no advisory.
4 min read

By the numbers
- npm packages published by one operator
- 12
- total downloads, per Checkmarx
- 40,767
- downloads of function-flag alone
- 37,419
- when the first package appeared
- Aug 2023
A single attacker has been publishing malware to npm since August 2023, and some of it was still installable at the end of September 2026. Security firm CloudSEK named the campaign MALFEX on September 30. It found one malicious package that no security advisory had flagged for 14 months. Checkmarx followed on October 5 with a count of 40,767 downloads across the campaign's packages. If any of them is in your dependency tree, a Windows machine that installed it may be running a remote-access tool.
How the attack works
npm is the package registry for JavaScript. When you install a package, npm can run a "postinstall" script, a command the package author chose. MALFEX uses that script to download and launch Windows malware the moment a developer runs npm install.
The payloads hide in plain sight. CloudSEK says the scripts download Windows programs disguised as PNG images. Checkmarx traced three separate delivery paths.
- Overlord RAT. The packages
tlxbnhd,tldriverandmxdriverfetch a fake PNG from api.imghippo.com. Inside are a signed AutoIt3 program and an encrypted script that loads Overlord, an open-source remote-access tool written in Go. A remote-access tool, or RAT, lets the attacker control the machine from afar. - A data stealer. A chain of
native-runner,img-to-nativeandcdn-img-fetchpulls an encrypted program from a GitHub account named "cavecrew." It then downloads a 64 MB Node.js stealer that Checkmarx calls "movinlike." - A long-running downloader.
function-flagkeeps pulling new payloads from rotating hosts, including discloud.app, squareweb.app, render.com and a Discord CDN proxy.
All three paths target Windows. Checkmarx notes that the downloader fails on macOS and Linux, because a Windows-only setting it relies on does not exist there.
What it steals and how it hides
Overlord has no fixed server address. "It can read encrypted memos that the operator posts in Solana transactions, decrypt them, and use the result as its server list," Checkmarx writes. Solana is a public blockchain, so the operator can move servers without changing the malware.
The stealer targets eight Discord clients and cookies from Chrome, Edge, Brave, Opera, Vivaldi and Yandex. It also goes after Telegram Desktop and the MetaMask, Phantom and Coinbase crypto wallets. Stolen data leaves through a Discord webhook, which Checkmarx says was created on September 26, 2026.
Persistence is quiet too. Checkmarx found a scheduled task named \Maiden that runs every five minutes, with its date set back to January 1, 2020. The operator also pushed malicious code far to the right with spaces, so it sits beyond the edge of a normal editor window.
CloudSEK says the operator signs the work as "Murizada" across several handles, including malfexkkj, malfex_user and cavecrew.
The packages to check
| Package | Role | Downloads, per Checkmarx | Status |
|---|---|---|---|
| function-flag | Downloader | 37,419 | Live, no advisory |
| function-color | Not stated | 300 | Live, no advisory |
| cdn-img-fetch | Stealer chain | 643 | Advisory covers only 1.0.0-1.0.1 |
| img-to-native | Stealer chain | 967 | Advised |
| native-runner | Stealer chain | 872 | Listed by Checkmarx |
| tlxbnhd | Overlord RAT | 139 | Seized |
| tldriver | Overlord RAT | 138 | Seized |
| mxdriver | Overlord RAT | 289 | Seized |
The two firms count slightly differently. CloudSEK lists function-flag, cdn-img-fetch and function-color as still installable. "The three packages without advisories are the only active threats defenders can target today," it writes. Checkmarx explains the gap on cdn-img-fetch: its advisory, MAL-2026-17320, covers versions 1.0.0 and 1.0.1, but the malicious versions are 1.0.2 and 1.0.3.
Checkmarx says the operator published 12 packages in all: eight malicious and four harmless decoys. In the week to October 1, the packages still drew 3,017 downloads.
Developers have been a frequent target this month. Earlier in October, a separate campaign was reported hiding malware in Git post-checkout hooks inside fake recruiter repositories.
What this means for developers
- Search your lockfiles now. Look for every package name in the table in
package-lock.json,yarn.lockorpnpm-lock.yaml, including transitive dependencies.npm ls <name>shows where a package came from. - Do not trust advisories alone. The
cdn-img-fetchadvisory covers the wrong versions, and two live packages had none. A cleannpm auditdoes not prove you are safe from this campaign. - Turn off install scripts where you can.
npm install --ignore-scripts, orignore-scripts=truein.npmrc, stops postinstall code from running. Allow scripts only for packages that need them. - Check Windows machines that installed a listed package. Look for a scheduled task named
\Maidenand a file namednode_runtime_helper.exeunder%APPDATA%\Microsoft\Windows\. Checkmarx also lists the address 104.234.65.75 on port 700 as a download server. - Rotate what the stealer takes. If a machine was hit, sign out of Discord and Telegram, clear browser sessions, change saved passwords and move funds out of any browser wallet.
The 37,419 downloads of function-flag are the number to remember. One small utility with a plain name carried almost the whole campaign.
Sources
Related articles

npm trusted publishing can now move dist-tags over OIDC
npm trusted publishing can now add, move and remove dist-tags such as latest with short-lived OIDC tokens. It is off by default and needs npm 11.21.0.

Node.js 22.23.3 LTS fixes an HTTP/2 use-after-free bug
Node.js 22.23.3 LTS, out September 23, fixes an HTTP/2 use-after-free bug, adds SharedArrayBuffer support to Node-API and moves to OpenSSL 3.5.8.

Rejetto HFS CVE-2026-61500 exploited a day after write-up
HFS 3.0.0 to 3.2.0 signs logins with Math.random(), a flaw Anthropic's Mythos found. Attacks began October 3, a day after the write-up. 3.2.1 fixes it.
The weekly digest
One email every Friday with the week's top stories from all six desks: AI, dev tools, coding, the tech industry, startups and what's next. Free, no spam.