MALFEX npm campaign ran 3 years, hit 40,000 downloads
CloudSEK details MALFEX, a single-operator npm campaign active since 2023: 8 malicious packages, 40,000+ downloads, delivering the Overlord RAT and an infostealer.
A single operator ran a malicious npm campaign for roughly three years, racking up more than 40,000 downloads across eight malicious packages before anyone flagged it. CloudSEK's threat-intelligence team named the operation MALFEX and dates it to August 2023. The research is CloudSEK's; it was also covered by SecurityWeek.
What it is
Per CloudSEK, the operator published at least twelve packages to npm — eight of them malicious — plus a payload repository on GitHub, all tied to one actor active since August 2023. The standout package, function-flag, accumulated over 37,000 downloads and has been malicious since July 18, 2025.
As of early October, three packages remained installable:
function-flag— continuously malicious since mid-2025function-color— a wrapper that pullsfunction-flagin as a dependencycdn-img-fetch— still installable after npm removed its parent package,img-to-native
What it drops
CloudSEK describes a postinstall delivery chain that downloads a Windows PE executable disguised as an image/png from a public image host, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and an encrypted script, and runs it. The payload is a build of overlord-client, an open-source Go RAT that Jamf Threat Labs documented in August 2026, with capabilities including screen capture, keylogging, remote shell, and file search. CloudSEK reports this particular build carries a previously undocumented live Solana blockchain C2 resolver. A separate Node.js information stealer targets browsers, Discord clients, and cryptocurrency wallets.
Indicators
CloudSEK attributes the operation to the team string malfexteam2027 and the GitHub account cavecrew, with command-and-control infrastructure including a Discord webhook and the endpoint 104.234.65.75:700. Pull the full IOC set from the CloudSEK writeup before building detections — do not rely on this summary.
Action checklist
- Search your dependency trees for
function-flag,function-color,cdn-img-fetch, andimg-to-native. CloudSEK notes no legitimate, widely-used package depends on the operator's packages, so exposure is limited to systems that installed these names directly. - Hunt for the delivery chain on developer and build hosts: unexpected
image/pngdownloads that are actually PE files, IExpress cabinet extraction, and AutoIt3 execution spawned from Node. - Block the C2 endpoint reported by CloudSEK and review egress to the Solana RPC endpoints and Discord webhooks the stealer uses.
- Rotate secrets on any host that installed a flagged package — this campaign steals browser credentials, Discord tokens, and wallet material.
Context
MALFEX is the latest in a run of npm supply-chain incidents we've tracked — from the RedHat-flagged "miasma" chain to 14 typosquats harvesting cloud secrets. What's notable here is dwell time: three years of availability and 40,000 downloads before detection, against packages with plausible utility names. The registry's scale makes low-download, long-lived packages a comfortable place to hide, and a wrapper that quietly re-exports a malicious dependency (function-color → function-flag) is a reminder that removing one package name doesn't clear the campaign.