Checkmarx and CloudSEK Detail MALFEX, an npm Campaign With Eight Malicious Packages and 40,767 Downloads, Three of Them Still Live
Researchers say a lone operator published 12 npm packages since August 2023, eight malicious; Checkmarx found three still installable on September 29 with incomplete advisory coverage.
Overview
Security researchers have detailed a long-running npm supply-chain campaign that targets Windows machines with information stealers and a remote access trojan. According to The Hacker News, the campaign has been codenamed MALFEX by CloudSEK and Checkmarx, and the activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious. Checkmarx’s write-up, dated October 5, 2026, puts the total at 40,767 downloads across the eight packages.
What We Know
The packages. The Hacker News lists the malicious packages as tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color and cdn-img-fetch, and marks the last three as still live when it published on October 7. Of the 40,767 downloads, The Hacker News says 37,419 correspond to function-flag, the largest driver of the activity.
Three delivery paths. The Hacker News says the attack is designed to infect Windows systems through three separate pathways. Three packages, tlxbnhd, tldriver and mxdriver, act as loaders for Overlord, an open-source remote access trojan written in Go that, per the same report, uses Solana transactions to extract the command-and-control address. A second group of packages chains img-to-native and cdn-img-fetch to deliver a Node.js stealer that, according to Checkmarx, targets Discord clients, browsers, Telegram Desktop session data and cryptocurrency wallets. The third path is function-flag, a downloader that runs from a postinstall hook; Checkmarx says its routine fails silently on macOS and Linux because the Windows-specific environment variable it relies on is undefined there.
Registry status and advisory gaps. Checkmarx reports that img-to-native and native-runner were seized by npm, while tlxbnhd, tldriver and mxdriver were unpublished. As of September 29, 2026, it says function-flag (37,419 lifetime downloads, 533 in the past week), function-color (300 lifetime) and cdn-img-fetch (643 lifetime) remained live. On advisories, Checkmarx writes that “function-flag and function-color have no advisory at all, and the cdn-img-fetch advisory (MAL-2026-17320, published 30 September) lists only versions 1.0.0 and 1.0.1, not the malicious 1.0.2 and 1.0.3.” It adds that tooling relying only on advisory feeds will miss them.
Why removal was not enough. The function-color package, per The Hacker News, embeds no payload of its own but lists function-flag as a dependency. Checkmarx says the stealer chain’s img-to-native package requires cdn-img-fetch purely to trigger execution, and that cdn-img-fetch stayed installable after img-to-native was seized. Its guidance is that when a package is removed from a registry, its dependencies should be reviewed as well.
Install-script blocking is only a partial defense. Checkmarx advises not to rely on the npm option that disables lifecycle scripts alone, saying it stops the Overlord loaders and function-flag but not the stealer chain, which runs when the package is loaded rather than through an install hook. A previously reported npm case also involved malware that avoided install-script defenses. For hosts where an affected package was installed on Windows, Checkmarx says to treat the machine as compromised even if node_modules was deleted, and to purge the packages from private registries, proxies and caches.
Attribution caveats. CloudSEK, quoted by The Hacker News, says the operator is Portuguese-speaking, with git commits at -0300 and a repository description in Portuguese. It cautions: “None of this is an argument that the campaign targets Brazil. It is a piece of attribution to the operator’s own linguistic space and nothing more.” The report also says Overlord has been observed in two other campaigns since July 2026, including a macOS fake Zoom installer campaign that shares tactical overlaps with a suspected North Korea-aligned cluster dubbed UNK_DeadDrop; it does not tie MALFEX itself to that cluster.
What We Don’t Know
- Whether the three packages listed as live have since been removed or covered by advisories; the figures above reflect Checkmarx’s September 29 check and The Hacker News report of October 7.
- How many of the 40,767 downloads, which are registry counts, resulted in an actual infection on a Windows host. The reports cited here give download counts, not infection figures.
- Who the operator is beyond the branding and language indicators the researchers describe.
Analysis
The case illustrates a gap the researchers themselves highlight: a registry takedown or an advisory can cover a package while leaving a dependency that carries the payload online. Teams that gate installs on advisory feeds alone, rather than on dependency review, would not have been alerted to the three packages Checkmarx describes as live with either no advisory or only partial advisory coverage.