MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
MALFEX: Malicious npm postinstall supply-chain campaign (TL-2026-2801), also tracked as MALFEX, is a high-severity supply-chain compromise, first published 2026-09-30. It is attributed to MALFEX operator with medium confidence, affects npm tlxbnhd, tldriver, mxdriver (Arm A droppers), maps to 11 MITRE ATT&CK techniques (T1027.013, T1036.005, T1053.005), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-2801
- Threat ID
- TL-2026-2801
- Also known as
- MALFEX
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution
- MALFEX operator
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, gaming, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in MALFEX: Malicious npm postinstall supply-chain campaign
Malware and tooling: Overlord, Rakhni, movinlike
CloudSEK attributes a 36-month npm supply-chain campaign (Aug 2023 - Sep 2026) to a single operator using two delivery arms to deploy the Overlord Go RAT and the movinlike Node.js stealer on Windows. The postinstall package function-flag was malicious from 2025-07-18 yet went unadvised for about 14 months, and function-flag and cdn-img-fetch remained unadvised and installable at report time.
How MALFEX: Malicious npm postinstall supply-chain campaign works
CloudSEK (Vikas Kundu, 2026-09-30) reports a campaign it names MALFEX: one operator publishing roughly 12 malicious npm packages across 8+ throwaway publisher accounts between August 2023 and September 2026. Each package used a fresh npm account with a randomized iCloud email. The operator left a hardcoded key string, malfexteam2027, in payload decryption logic, and a GitHub account (cavecrew, commits at UTC-0300) hosts payloads and a public process-hollowing PoC. A cdn-img-fetch@1.0.9 README states it was made by the 'Malfex team' whose owner is 'Murizada'.
Delivery Arm A is a dropper trio (tlxbnhd, tldriver, mxdriver) whose postinstall scripts download a Windows PE disguised as a PNG from api.imghippo.com. The PE is a Microsoft IExpress cabinet holding a signed AutoIt3 interpreter and an encrypted a3x script (EA06 encryption with RC4 key 8448433, plus cycled-XOR strings). The chain executes an Overlord-client Go RAT build, persists via the AutoIt3.exe copy under %LOCALAPPDATA%\ScopeSmart Technologies Inc and the scheduled task \Maiden, and drops gldriver_pre_core.exe and gldriver_pre_asset.exe. CloudSEK reports the RAT's Solana-blockchain memo C2 channel as live in this build; Jamf had described the Solana resolver as present but disabled in a separate macOS sample.
Delivery Arm B (function-flag with wrapper function-color; cdn-img-fetch; img-to-native; native-runner; centralizemiddle as benign cover) retrieves a PNG polyglot from raw.githubusercontent.com/cavecrew/proj, decrypts the embedded payload with the malfexteam2027 key, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700. Per OSV/Amazon Inspector, img-to-native (MAL-2026-17216) reads an encrypted blob appended after the PNG IEND marker in cdn-img-fetch's cached banner.jpg, decrypts it with AES-256-CBC (key derived from sha256 of 'nif-runtime-2027'), and writes node_runtime_helper.exe to %LOCALAPPDATA%\Programs\NodeRuntime; native-runner (MAL-2026-17218) polls for %APPDATA%\Microsoft\Windows\node_runtime_helper.exe and spawns it hidden and detached. The movinlike stealer injects into Discord clients, steals browser cookies and Telegram tdata, and exfiltrates over a Discord webhook that was live at report time.
Four OSV advisories were issued 2026-09-22 to 2026-09-28, but function-flag and cdn-img-fetch stayed unadvised and installable, and img-to-native's seizure left its active dependency reachable. No CVE applies. Severity HIGH is an analyst assessment: the sources give no CVSS or severity rating.
MITRE ATT&CK techniques used in TL-2026-2801
Defense Evasion
T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
Persistence
Execution
Initial Access
T1195.002 Compromise Software Supply Chain
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Exfiltration
Affected products and versions in MALFEX: Malicious npm postinstall supply-chain campaign
- npm — tlxbnhd, tldriver, mxdriver (Arm A droppers)
Vulnerable versions: all published versions - npm — function-flag, function-color, cdn-img-fetch (unadvised at report time)
Vulnerable versions: all published versions - npm — img-to-native, native-runner
Vulnerable versions: 1.0.0; 1.0.1; 1.0.2; 1.0.3
Remediation for MALFEX: Malicious npm postinstall supply-chain campaign
Patches
- No patch; remove the malicious packages. Advisories: MAL-2026-17216, MAL-2026-17218
Immediate actions
- Uninstall and block function-flag, cdn-img-fetch, function-color, img-to-native, native-runner, tlxbnhd, tldriver and mxdriver in npm/registry proxies and lockfiles
- Treat any host that installed these packages as fully compromised; rotate credentials, tokens and Discord/Telegram sessions from a clean device
- Block outbound traffic to 104.234.65.75:700 and api.imghippo.com from build/dev hosts; review raw.githubusercontent.com/cavecrew/ access
- Hunt for \Maiden scheduled task, %LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe, gldriver_pre_core.exe, gldriver_pre_asset.exe and node_runtime_helper.exe
Workarounds
- Use a private registry mirror with malware scanning and package age/reputation gating
Longer-term hardening
- Run npm installs in CI with --ignore-scripts by default and allowlist postinstall scripts
- Add dependency-tree inspection (transitive and caret-range dependencies) to package vetting
- Alert on Node.js processes spawning hidden detached executables from %APPDATA% or %LOCALAPPDATA%
Weaknesses (CWE) in MALFEX: Malicious npm postinstall supply-chain campaign
CWE-506
Timeline of MALFEX: Malicious npm postinstall supply-chain campaign
- Earliest activity of the single-operator MALFEX npm campaign per CloudSEK (August 2023; day approximate)
- npm package function-flag becomes continuously malicious; it then goes unadvised for about 14 months
- Jamf Threat Labs documents an Overlord RAT build delivered via a fake Zoom installer on macOS, with the Solana C2 resolver disabled; it does not identify npm as a delivery path
- First of four OSV/Amazon Inspector advisories covering MALFEX packages issued (window 2026-09-22 to 2026-09-28)
- MAL-2026-17216 (img-to-native) and MAL-2026-17218 (native-runner) published; advisory text names the malfexteam2027 operator identifier
- CloudSEK publishes MALFEX report: two arms, Overlord RAT and movinlike stealer; function-flag and cdn-img-fetch still unadvised and installable, Discord exfil webhook live
Sources cited for MALFEX: Malicious npm postinstall supply-chain campaign
- MALFEX - A malicious npm postinstall no advisory has caught for fourteen months (CloudSEK)
- CloudSEK MALFEX full report (PDF)
- OSV MAL-2026-17216: Malicious code in img-to-native (npm)
- OSV MAL-2026-17218: Malicious code in native-runner (npm)
- GHSA-pv7p-ghgv-268x (img-to-native)
- GHSA-jxw5-69p3-hpm4 (native-runner)
- Jamf Threat Labs: Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS
- Overlord RAT threat profile
More in supply chain
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
Detection coverage for TL-2026-2801
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2801 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.