The MALFEX npm malware campaign has quietly run since 2023, and three of its packages were still installable in early October 2026. If you’ve installed any of the eight packages listed below, treat that machine as compromised. The payloads only run on Windows, but the install scripts still fire everywhere.
Quick Facts
- Security firm Checkmarx published its write-up on October 5, 2026; CloudSEK reported on the campaign on September 30.
- Eight of 12 packages tied to one operator are malicious, with 40,000+ downloads combined.
- Still installable as of late September:
function-flag,function-color, andcdn-img-fetch. - Payloads target Windows: a remote-access trojan, a data stealer, and a downloader.
The short version: this isn’t a bug in npm itself. Someone published look-alike utility packages and waited for developers to install them.
What the MALFEX npm malware actually does
The attack starts with a postinstall script, which npm runs automatically right after a package installs. That script downloads a Windows program disguised as a harmless image file. On macOS and Linux, the downloader fails silently, so you won’t see an error either.
According to CloudSEK, the malicious postinstall in function-flag went unflagged by advisory databases for 14 months. That’s a long time for a package with 37,419 lifetime downloads.
The same operator uses one npm account naming scheme, a shared encryption key, and the same GitHub identity across packages. That’s sloppy tradecraft, but it still worked for years.
The eight packages and their three payloads
Checkmarx groups the packages by what they install. The table below shows which package leads to which payload.
| Payload | Packages | What it does |
|---|---|---|
| Overlord RAT | tlxbnhd, tldriver, mxdriver | Screen capture, keylogging, clipboard capture, remote shell |
| movinlike stealer | cdn-img-fetch, img-to-native, native-runner | Steals Discord, browser, Telegram and crypto wallet data |
| Downloader | function-flag, function-color | Fetches and runs more Windows executables |
Why this matters: advisory coverage is patchy. SecurityWeek notes the advisory for cdn-img-fetch covers only two of its four malicious versions. A clean scan doesn’t prove you’re safe.
Why this npm supply chain attack lasted so long
Most of these packages looked boring. Names like function-color and cdn-img-fetch sound like small helper libraries, the kind you might add without a second thought. Four of the 12 packages tied to the operator were harmless, which helped the rest blend in.
The delivery chain also hid its tracks. The first download pretends to be a PNG image, and Checkmarx says the stealer chain hands off through several small packages instead of one obvious one. The remote-access trojan reads its instructions from Solana blockchain transactions, which makes the control server harder to block.
Because no widely used package depends on these, the damage came from direct installs. That means people chose to install them, so it pays to be careful with copied commands and unfamiliar suggestions. It’s a good reason to look up any unfamiliar package name before you run npm install.
How to check your projects for MALFEX
Start with your dependency tree, including packages pulled in indirectly. This command searches for all eight names at once:
npm ls --all 2>/dev/null | grep -E "tlxbnhd|tldriver|mxdriver|cdn-img-fetch|img-to-native|native-runner|function-flag|function-color"
No output means none of them are in that project. Run it in each repo and on your CI machines too.
On Windows, also look for signs the payload already ran. Per CloudSEK, check for:
- A scheduled task named
\Maiden. - A folder called
ScopeSmart Technologies Incunder%LOCALAPPDATA%, containingAutoIt3.exe.
Either one means the malware ran, and you should isolate the PC before doing anything else.
What to do if you installed one
Disconnect the Windows machine, delete the scheduled task and the persistence folder, then do the rest from a clean device. Change your Discord, browser-saved, and crypto wallet credentials, and sign out of Telegram sessions everywhere.
Checkmarx also warns against relying only on npm install --ignore-scripts. It helps, but it isn’t a full defense on its own. A better habit is to pin exact versions, review new dependencies before adding them, and block unknown packages at a registry proxy if your team uses one.
This isn’t the first developer-tool scare we’ve covered. See our posts on the Mistral Vibe vulnerability and the GitHub Copilot CLI vulnerability for similar cases where a dev tool became the way in.
Frequently Asked Questions
Am I affected by the MALFEX npm malware if I use a Mac or Linux?
The payloads are built for Windows, and the downloader fails silently on macOS and Linux. Still, remove the packages and check your CI runners, since some of those run Windows.
Are the MALFEX packages still on npm?
Five were removed. As of late September, function-flag, function-color, and cdn-img-fetch were still installable, so check npm’s current status before assuming they’re gone.
How do I know if my PC ran the malware?
Look for the \Maiden scheduled task and the ScopeSmart Technologies Inc folder in your local app data. If either exists, treat the PC as compromised.
Does npm audit catch these packages?
Not reliably. Advisory coverage is incomplete, and one package has advisories for only half its malicious versions. Search for the names directly.
My take: run that one-line search today, even if you think you’d never install a package called function-flag. Transitive dependencies are how these things sneak in. If you come up empty, you’ve spent thirty seconds. If you don’t, you’ve saved yourself a very bad week.


Leave a Reply