MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer

MALFEX: Malicious npm postinstall supply-chain campaign (TL-2026-2801), also tracked as MALFEX, is a high-severity supply-chain compromise, first published 2026-09-30. It is attributed to MALFEX operator with medium confidence, affects npm tlxbnhd, tldriver, mxdriver (Arm A droppers), maps to 11 MITRE ATT&CK techniques (T1027.013, T1036.005, T1053.005), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2801

Threat ID
TL-2026-2801
Also known as
MALFEX
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-09-30
Last reviewed
2026-09-30
Attribution
MALFEX operator
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
technology, software-development, gaming, consumer
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in MALFEX: Malicious npm postinstall supply-chain campaign

Malware and tooling: Overlord, Rakhni, movinlike

CloudSEK attributes a 36-month npm supply-chain campaign (Aug 2023 - Sep 2026) to a single operator using two delivery arms to deploy the Overlord Go RAT and the movinlike Node.js stealer on Windows. The postinstall package function-flag was malicious from 2025-07-18 yet went unadvised for about 14 months, and function-flag and cdn-img-fetch remained unadvised and installable at report time.

How MALFEX: Malicious npm postinstall supply-chain campaign works

CloudSEK (Vikas Kundu, 2026-09-30) reports a campaign it names MALFEX: one operator publishing roughly 12 malicious npm packages across 8+ throwaway publisher accounts between August 2023 and September 2026. Each package used a fresh npm account with a randomized iCloud email. The operator left a hardcoded key string, malfexteam2027, in payload decryption logic, and a GitHub account (cavecrew, commits at UTC-0300) hosts payloads and a public process-hollowing PoC. A cdn-img-fetch@1.0.9 README states it was made by the 'Malfex team' whose owner is 'Murizada'.

Delivery Arm A is a dropper trio (tlxbnhd, tldriver, mxdriver) whose postinstall scripts download a Windows PE disguised as a PNG from api.imghippo.com. The PE is a Microsoft IExpress cabinet holding a signed AutoIt3 interpreter and an encrypted a3x script (EA06 encryption with RC4 key 8448433, plus cycled-XOR strings). The chain executes an Overlord-client Go RAT build, persists via the AutoIt3.exe copy under %LOCALAPPDATA%\ScopeSmart Technologies Inc and the scheduled task \Maiden, and drops gldriver_pre_core.exe and gldriver_pre_asset.exe. CloudSEK reports the RAT's Solana-blockchain memo C2 channel as live in this build; Jamf had described the Solana resolver as present but disabled in a separate macOS sample.

Delivery Arm B (function-flag with wrapper function-color; cdn-img-fetch; img-to-native; native-runner; centralizemiddle as benign cover) retrieves a PNG polyglot from raw.githubusercontent.com/cavecrew/proj, decrypts the embedded payload with the malfexteam2027 key, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700. Per OSV/Amazon Inspector, img-to-native (MAL-2026-17216) reads an encrypted blob appended after the PNG IEND marker in cdn-img-fetch's cached banner.jpg, decrypts it with AES-256-CBC (key derived from sha256 of 'nif-runtime-2027'), and writes node_runtime_helper.exe to %LOCALAPPDATA%\Programs\NodeRuntime; native-runner (MAL-2026-17218) polls for %APPDATA%\Microsoft\Windows\node_runtime_helper.exe and spawns it hidden and detached. The movinlike stealer injects into Discord clients, steals browser cookies and Telegram tdata, and exfiltrates over a Discord webhook that was live at report time.

Four OSV advisories were issued 2026-09-22 to 2026-09-28, but function-flag and cdn-img-fetch stayed unadvised and installable, and img-to-native's seizure left its active dependency reachable. No CVE applies. Severity HIGH is an analyst assessment: the sources give no CVSS or severity rating.

MITRE ATT&CK techniques used in TL-2026-2801

Defense Evasion

T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

Persistence

T1053.005 Scheduled Task

Execution

T1059.007 JavaScript

Initial Access

T1195.002 Compromise Software Supply Chain

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in MALFEX: Malicious npm postinstall supply-chain campaign

  • npm — tlxbnhd, tldriver, mxdriver (Arm A droppers)
    Vulnerable versions: all published versions
  • npm — function-flag, function-color, cdn-img-fetch (unadvised at report time)
    Vulnerable versions: all published versions
  • npm — img-to-native, native-runner
    Vulnerable versions: 1.0.0; 1.0.1; 1.0.2; 1.0.3

Remediation for MALFEX: Malicious npm postinstall supply-chain campaign

Patches

  • No patch; remove the malicious packages. Advisories: MAL-2026-17216, MAL-2026-17218

Immediate actions

  • Uninstall and block function-flag, cdn-img-fetch, function-color, img-to-native, native-runner, tlxbnhd, tldriver and mxdriver in npm/registry proxies and lockfiles
  • Treat any host that installed these packages as fully compromised; rotate credentials, tokens and Discord/Telegram sessions from a clean device
  • Block outbound traffic to 104.234.65.75:700 and api.imghippo.com from build/dev hosts; review raw.githubusercontent.com/cavecrew/ access
  • Hunt for \Maiden scheduled task, %LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe, gldriver_pre_core.exe, gldriver_pre_asset.exe and node_runtime_helper.exe

Workarounds

  • Use a private registry mirror with malware scanning and package age/reputation gating

Longer-term hardening

  • Run npm installs in CI with --ignore-scripts by default and allowlist postinstall scripts
  • Add dependency-tree inspection (transitive and caret-range dependencies) to package vetting
  • Alert on Node.js processes spawning hidden detached executables from %APPDATA% or %LOCALAPPDATA%

Weaknesses (CWE) in MALFEX: Malicious npm postinstall supply-chain campaign

CWE-506

Timeline of MALFEX: Malicious npm postinstall supply-chain campaign

  • Earliest activity of the single-operator MALFEX npm campaign per CloudSEK (August 2023; day approximate)
  • npm package function-flag becomes continuously malicious; it then goes unadvised for about 14 months
  • Jamf Threat Labs documents an Overlord RAT build delivered via a fake Zoom installer on macOS, with the Solana C2 resolver disabled; it does not identify npm as a delivery path
  • First of four OSV/Amazon Inspector advisories covering MALFEX packages issued (window 2026-09-22 to 2026-09-28)
  • MAL-2026-17216 (img-to-native) and MAL-2026-17218 (native-runner) published; advisory text names the malfexteam2027 operator identifier
  • CloudSEK publishes MALFEX report: two arms, Overlord RAT and movinlike stealer; function-flag and cdn-img-fetch still unadvised and installable, Discord exfil webhook live

Sources cited for MALFEX: Malicious npm postinstall supply-chain campaign

More in supply chain

Detection coverage for TL-2026-2801

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2801 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats