// 2 CRITICAL · 2 ZERO-DAY · 4 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
The MALFEX campaign has distributed over 40,000 downloads of malicious npm packages. function-flag remains installable with over 37,000 downloads and no security advisory.

On October 1, 2026, a developer types npm install function-flag and receives a package Checkmarx classified as malicious fourteen months earlier. No advisory flags it. The same holds for function-color and cdn-img-fetch: three utility-library names, three payloads still live in the public registry.

The MALFEX campaign has amassed over 40,000 downloads since 2023 across eight malicious packages. The bulk — over 37,000 — belongs to function-flag, installable without any security warning since July 2025. Checkmarx and CloudSEK agree on the structural data, but neither source is an official npm registry advisory.

Key Takeaways
  • Eight MALFEX packages: over 40,000 total downloads; three still installable as of October 1, 2026.
  • function-flag: over 37,000 downloads since July 2025, zero security advisory, fourteen months of silence.
  • Three independent delivery paths: Overlord RAT, Node.js stealer movinlike, version-specific downloader.
  • The Solana C2 resolver is active in the Overlord build, unlike previous campaigns where it was disabled.
  • The payload activates on Windows via postinstall lifecycle hooks; it fails silently on macOS and Linux.

The Three Ghost Packages

Checkmarx, via SecurityWeek, tracked twelve packages published from August 2023: eight malicious, five removed, six with OSV advisories. The rest is a void. function-flag, function-color and cdn-img-fetch persist in the registry without security flags.

function-flag is the edge case. Checkmarx flags it as "malicious since July 2025, with more than 37,000 downloads, and no advisory flags it as malicious." CloudSEK adds the time dimension: fourteen months. For cdn-img-fetch, coverage is partial: OSV advisories issued by Amazon Inspector between September 22 and 28, 2026 cover two of the four malicious iterations.

Infection triggers during npm install, exploiting postinstall lifecycle hooks. On macOS and Linux the routine fails silently: the payload is Windows-only. Checkmarx finds no dependencies on legitimate packages and no geographic or organizational targeting.

From IExpress to Solana C2

CloudSEK documented three delivery paths with no shared infrastructure. The first uses a Windows PE disguised as image/png, extracted via IExpress cabinet with a signed AutoIt3 interpreter. The encrypted script generates the overlord-client build, a RAT with screen capture, keylogging, window monitoring, remote shell, file search and hidden desktop.

The technical novelty lies in command and control. CloudSEK observes that "the Solana-memo C2 resolver Jamf described as 'present but disabled' is hardcoded as active literal strings," providing "the first observed sample where the mechanism is actually available." The Solana blockchain serves as the C2 server resolver.

The second path retrieves a polyglot PNG from raw.githubusercontent.com, decrypts it with the hardcoded key malfexteam2027, and downloads the Node.js movinlike bundle (64 MB) from 104.234.65.75:700. The stealer injects into eight Discord clients, harvests data from seven browsers and cryptocurrency wallets, and exfiltrates to a Discord webhook CloudSEK found active at the time of the report.

The third path, exclusive to function-flag, varies the downloader in every version to fetch payloads from different locations.

The Operator and Their Aliases

The operator identifies as malfexteam2027. The string appears as a key-derivation constant and in the README of function-flag@1.7.3. The GitHub account cavecrew (display name muriel) uses the email corpmalfex@gmail.com. The public repository hosts the two core techniques: Windows credential stealer and process-hollowing proof-of-concept. CloudSEK links five npm handles to the same operator.

These identity details come from CloudSEK's self-assessment of the discovery: internally consistent, but not independently verifiable from available sources.

What to Do Now

The first specific action: check for function-flag, function-color or cdn-img-fetch in npm lockfiles generated before October 1, 2026. The registry has not blocked them; manual removal is the only way.

The second action: scan npm install logs on Windows systems for references to packages with names resembling utility libraries — function-*, *-fetch, *-native — that could mask MALFEX payloads.

The third action: monitor OSV advisories issued by Amazon Inspector, the only mechanism that partially covered cdn-img-fetch, for any extension of coverage to the three remaining packages.

The case raises a systemic question. When a package with over 37,000 downloads can remain malicious for fourteen months without an advisory, the npm registry's detection mechanism isn't slow — it's nonexistent for this class of threat.

"The three packages without advisories are the only active threats defenders can target today" — CloudSEK

The Banality of the Name, the Sophistication of the Payload

function-flag. function-color. cdn-img-fetch. Names from a tutorial, from a forgotten dependency, from a line in a file no one reads. Yet one of these names carried a RAT with blockchain C2, a stealer with an active webhook, fourteen months of silence.

The contrast isn't irony: it's the method. The operator bet on negligence — the registry's, the developer who installs without checking, the system that doesn't distinguish a silent error on macOS from a real threat on Windows. They won three times out of eight. And as of October 1, 2026, they're still waiting for the next npm install.

How many other function-flags exist, waiting only to be searched for?

Sources: SecurityWeek/Checkmarx; CloudSEK. Operator identity details come from self-assessment of the discovery and are not independently verifiable. No official npm advisory has been issued for the three remaining packages at time of publication.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. securityweek.com
  2. radar.offseq.com
  3. cloudsek.com
  4. unit42.paloaltonetworks.com
  5. cyfirma.com
  6. podcast.securityweek.com