Skip to content

MALFEX npm campaign ran 3 years, hit 40,000 downloads

CloudSEK details MALFEX, a single-operator npm campaign active since 2023: 8 malicious packages, 40,000+ downloads, delivering the Overlord RAT and an infostealer.

Published 3 min read

A single operator ran a malicious npm campaign for roughly three years, racking up more than 40,000 downloads across eight malicious packages before anyone flagged it. CloudSEK's threat-intelligence team named the operation MALFEX and dates it to August 2023. The research is CloudSEK's; it was also covered by SecurityWeek.

What it is

Per CloudSEK, the operator published at least twelve packages to npm — eight of them malicious — plus a payload repository on GitHub, all tied to one actor active since August 2023. The standout package, function-flag, accumulated over 37,000 downloads and has been malicious since July 18, 2025.

As of early October, three packages remained installable:

  • function-flag — continuously malicious since mid-2025
  • function-color — a wrapper that pulls function-flag in as a dependency
  • cdn-img-fetch — still installable after npm removed its parent package, img-to-native

What it drops

CloudSEK describes a postinstall delivery chain that downloads a Windows PE executable disguised as an image/png from a public image host, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and an encrypted script, and runs it. The payload is a build of overlord-client, an open-source Go RAT that Jamf Threat Labs documented in August 2026, with capabilities including screen capture, keylogging, remote shell, and file search. CloudSEK reports this particular build carries a previously undocumented live Solana blockchain C2 resolver. A separate Node.js information stealer targets browsers, Discord clients, and cryptocurrency wallets.

Indicators

CloudSEK attributes the operation to the team string malfexteam2027 and the GitHub account cavecrew, with command-and-control infrastructure including a Discord webhook and the endpoint 104.234.65.75:700. Pull the full IOC set from the CloudSEK writeup before building detections — do not rely on this summary.

Action checklist

  1. Search your dependency trees for function-flag, function-color, cdn-img-fetch, and img-to-native. CloudSEK notes no legitimate, widely-used package depends on the operator's packages, so exposure is limited to systems that installed these names directly.
  2. Hunt for the delivery chain on developer and build hosts: unexpected image/png downloads that are actually PE files, IExpress cabinet extraction, and AutoIt3 execution spawned from Node.
  3. Block the C2 endpoint reported by CloudSEK and review egress to the Solana RPC endpoints and Discord webhooks the stealer uses.
  4. Rotate secrets on any host that installed a flagged package — this campaign steals browser credentials, Discord tokens, and wallet material.

Context

MALFEX is the latest in a run of npm supply-chain incidents we've tracked — from the RedHat-flagged "miasma" chain to 14 typosquats harvesting cloud secrets. What's notable here is dwell time: three years of availability and 40,000 downloads before detection, against packages with plausible utility names. The registry's scale makes low-download, long-lived packages a comfortable place to hide, and a wrapper that quietly re-exports a malicious dependency (function-color → function-flag) is a reminder that removing one package name doesn't clear the campaign.

Related stories