Skip to content

MALFEX npm malware ran undetected for 14 months

MALFEX, a one-person npm malware campaign, published 12 packages since 2023 and drew 40,767 downloads. Some packages are still live with no advisory.

By Tech AI Wire Team

4 min read

XLinkedIn
Screenshot of CloudSEK's blog post MALFEX - A malicious npm postinstall no advisory has caught for fourteen months, above the report's header image.

By the numbers

npm packages published by one operator
12
total downloads, per Checkmarx
40,767
downloads of function-flag alone
37,419
when the first package appeared
Aug 2023

A single attacker has been publishing malware to npm since August 2023, and some of it was still installable at the end of September 2026. Security firm CloudSEK named the campaign MALFEX on September 30. It found one malicious package that no security advisory had flagged for 14 months. Checkmarx followed on October 5 with a count of 40,767 downloads across the campaign's packages. If any of them is in your dependency tree, a Windows machine that installed it may be running a remote-access tool.

How the attack works

npm is the package registry for JavaScript. When you install a package, npm can run a "postinstall" script, a command the package author chose. MALFEX uses that script to download and launch Windows malware the moment a developer runs npm install.

The payloads hide in plain sight. CloudSEK says the scripts download Windows programs disguised as PNG images. Checkmarx traced three separate delivery paths.

  1. Overlord RAT. The packages tlxbnhd, tldriver and mxdriver fetch a fake PNG from api.imghippo.com. Inside are a signed AutoIt3 program and an encrypted script that loads Overlord, an open-source remote-access tool written in Go. A remote-access tool, or RAT, lets the attacker control the machine from afar.
  2. A data stealer. A chain of native-runner, img-to-native and cdn-img-fetch pulls an encrypted program from a GitHub account named "cavecrew." It then downloads a 64 MB Node.js stealer that Checkmarx calls "movinlike."
  3. A long-running downloader. function-flag keeps pulling new payloads from rotating hosts, including discloud.app, squareweb.app, render.com and a Discord CDN proxy.

All three paths target Windows. Checkmarx notes that the downloader fails on macOS and Linux, because a Windows-only setting it relies on does not exist there.

What it steals and how it hides

Overlord has no fixed server address. "It can read encrypted memos that the operator posts in Solana transactions, decrypt them, and use the result as its server list," Checkmarx writes. Solana is a public blockchain, so the operator can move servers without changing the malware.

The stealer targets eight Discord clients and cookies from Chrome, Edge, Brave, Opera, Vivaldi and Yandex. It also goes after Telegram Desktop and the MetaMask, Phantom and Coinbase crypto wallets. Stolen data leaves through a Discord webhook, which Checkmarx says was created on September 26, 2026.

Persistence is quiet too. Checkmarx found a scheduled task named \Maiden that runs every five minutes, with its date set back to January 1, 2020. The operator also pushed malicious code far to the right with spaces, so it sits beyond the edge of a normal editor window.

CloudSEK says the operator signs the work as "Murizada" across several handles, including malfexkkj, malfex_user and cavecrew.

The packages to check

PackageRoleDownloads, per CheckmarxStatus
function-flagDownloader37,419Live, no advisory
function-colorNot stated300Live, no advisory
cdn-img-fetchStealer chain643Advisory covers only 1.0.0-1.0.1
img-to-nativeStealer chain967Advised
native-runnerStealer chain872Listed by Checkmarx
tlxbnhdOverlord RAT139Seized
tldriverOverlord RAT138Seized
mxdriverOverlord RAT289Seized

The two firms count slightly differently. CloudSEK lists function-flag, cdn-img-fetch and function-color as still installable. "The three packages without advisories are the only active threats defenders can target today," it writes. Checkmarx explains the gap on cdn-img-fetch: its advisory, MAL-2026-17320, covers versions 1.0.0 and 1.0.1, but the malicious versions are 1.0.2 and 1.0.3.

Checkmarx says the operator published 12 packages in all: eight malicious and four harmless decoys. In the week to October 1, the packages still drew 3,017 downloads.

Developers have been a frequent target this month. Earlier in October, a separate campaign was reported hiding malware in Git post-checkout hooks inside fake recruiter repositories.

What this means for developers

  • Search your lockfiles now. Look for every package name in the table in package-lock.json, yarn.lock or pnpm-lock.yaml, including transitive dependencies. npm ls <name> shows where a package came from.
  • Do not trust advisories alone. The cdn-img-fetch advisory covers the wrong versions, and two live packages had none. A clean npm audit does not prove you are safe from this campaign.
  • Turn off install scripts where you can. npm install --ignore-scripts, or ignore-scripts=true in .npmrc, stops postinstall code from running. Allow scripts only for packages that need them.
  • Check Windows machines that installed a listed package. Look for a scheduled task named \Maiden and a file named node_runtime_helper.exe under %APPDATA%\Microsoft\Windows\. Checkmarx also lists the address 104.234.65.75 on port 700 as a download server.
  • Rotate what the stealer takes. If a machine was hit, sign out of Discord and Telegram, clear browser sessions, change saved passwords and move funds out of any browser wallet.

The 37,419 downloads of function-flag are the number to remember. One small utility with a plain name carried almost the whole campaign.

Sources

  1. MALFEX - A malicious npm postinstall no advisory has caught for fourteen months - CloudSEK
  2. MALFEX npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work - Checkmarx

Related articles

The weekly digest

One email every Friday with the week's top stories from all six desks: AI, dev tools, coding, the tech industry, startups and what's next. Free, no spam.

Unsubscribe anytime with one click.