malware
Published 2026-09-30
Verified 2026-10-06

MALFEX npm campaign: one operator since 2023, Overlord RAT and movinlike stealer for Windows; function-flag (37,000+ downloads) malicious for 14 months with no advisory

Checkmarx (5 October 2026) and CloudSEK (30 September 2026) describe MALFEX, an npm supply-chain malware campaign run by what appears to be one operator publishing since August 2023. Checkmarx counts twelve packages, eight of them malicious; CloudSEK's count is at least nine. The campaign has three delivery paths that do not share infrastructure: install scripts in tlxbnhd, tldriver and mxdriver that load the open-source Go remote access trojan Overlord (screen capture, keylogging, remote shell, hidden desktop; CloudSEK says this build has a working Solana-blockchain lookup for its command server); img-to-native, native-runner and cdn-img-fetch, which drop the Node.js stealer movinlike, aimed at Discord clients, browsers, crypto wallets and Telegram data and sending it out through a Discord webhook; and function-flag, where each malicious version downloads a payload from a different location. The scripts run on any OS but the payloads only work on Windows, and installs complete even when the download fails. Checkmarx says function-flag has been malicious since July 2025, has more than 37,000 downloads and still had no advisory, and that function-flag, function-color (which pulls it in) and cdn-img-fetch were still installable on 1 October; the cdn-img-fetch advisory MAL-2026-17320 covers only some malicious versions. Five packages have been removed. No legitimate, widely used package depends on them and neither firm saw geographic targeting. Primary: Checkmarx; also CloudSEK; wire: SecurityWeek (6 Oct).

Product
npm packages: function-flag, function-color, cdn-img-fetch, img-to-native, native-runner, tlxbnhd, tldriver, mxdriver
Versions
All malicious versions of the named packages (function-flag 2.3.4 is not malicious per Checkmarx); img-to-native and native-runner 1.0.0–1.0.3
Exploited in Australia?
unknown
Patch to
Search lockfiles and node_modules for the eight package names (a pinned malicious version can survive registry removal), and block them in your registry proxy. If any was installed on a Windows machine, isolate it, remove persistence, and rotate browser, Discord, Telegram, wallet, cloud and developer credentials from a clean device. Do not treat 'no advisory' as 'safe': scan new dependencies for install scripts and outbound downloads.

Primary: Checkmarx Zero — MALFEX npm malware campaign: three payloads and an adversary that signs their work (5 Oct 2026) · Vendor: CloudSEK — MALFEX: a malicious npm postinstall no advisory has caught for fourteen months (30 Sep 2026) · SecurityWeek — Long-running npm malware campaign accumulates 40,000 downloads (6 Oct 2026)

tech