- Checkmarx documented MALFEX, an npm campaign with eight malicious packages and 40,767 downloads. Two live packages had no malware advisory as of 29 September 2026.
- A scanner that relies only on advisory feeds would miss them. Blocking install scripts alone also misses one of the three delivery paths.
- Check lockfiles and resolved dependencies for all eight names, block them at the registry proxy, and treat any Windows host that installed one as compromised.
An advisory feed lists only what someone has entered into it. It does not list what is safe. A campaign on npm, the JavaScript package registry, shows how big that gap can be.
What Checkmarx found
Checkmarx says one apparent operator is behind MALFEX. Their activity on npm goes back to August 2023. The operator published twelve packages. Eight are malicious. Four hold no harmful code and served as cover.
When Checkmarx checked on 29 September 2026, anyone could still install three of the malicious packages from npm: function-flag, function-color and cdn-img-fetch. Six of the eight have malware advisories in the Open Source Vulnerabilities (OSV) database. Function-flag and function-color have none.
Even the advisory for cdn-img-fetch is partial. Entry MAL-2026-17320 stops at the first two releases. Builds 1.0.2 and 1.0.3 also carry malware, yet the entry does not mention them. Checkmarx warns that a scanner fed only by advisories would not flag these packages.
These numbers count registry downloads. They do not count infected machines. Some function-flag downloads come from function-color, which installs it. A download also does not prove an install on Windows.
The exposure is narrow. Checkmarx found no popular package that depends on any of these. Only systems that installed the names directly are at risk. It also found no sign that the operator picks victims by country or company.
Three paths, built to survive one fix
The three paths seem to share an actor but not infrastructure. Blocking one leaves the others working.
Path one uses the loaders tlxbnhd, tldriver and mxdriver. Their install scripts download a file labelled as a PNG image. It is really a self-extracting archive. Inside are a signed AutoIt interpreter and an encrypted script. The script unpacks the Overlord remote access trojan.
Overlord can capture the screen, log keystrokes and run a hidden desktop. It can also read encrypted notes posted in Solana blockchain transactions and use them as its server list. Swapping servers then needs only a new transaction. The build Checkmarx analysed had no address set. The team saw no command traffic in testing.
Path two has no install hook. The code runs when the package is loaded. The package img-to-native loads cdn-img-fetch, which downloads an image. An encrypted program is hidden after the picture data. That program fetches movinlike, a Node.js stealer.
The stealer targets eight Discord clients, seven browsers, Telegram sessions and crypto wallets. It sends the data to a Discord webhook. Checkmarx says that webhook was created on 26 September 2026.
Path three is function-flag, the longest-running part. Every malicious release has code in index.js that fetches a file. Each release uses a different web address. The attacker added blank spaces before those lines. That pushes them off-screen in a normal code editor.
The routine sits inside an empty catch block. If the download fails, the install still finishes with no error. The host for version 1.7.3 was offline, so Checkmarx could not recover that payload.
Where the usual defences fall short
This is WebPulse's analysis, not Checkmarx's wording. The case shows four common controls, each with a blind spot.
First, advisory feeds. The package with the most downloads had no advisory. Think of a recall list. A product missing from it has not been proven safe.
Second, blocking install scripts. Checkmarx says the --ignore-scripts setting stops the Overlord loaders and function-flag. It does not stop the stealer chain, which has no install hook.
Third, removing the visible package. npm seized img-to-native. But cdn-img-fetch, the package it loads, stayed available for download.
Fourth, a green build. A silent failure looks like success. The person running the install sees nothing wrong.
Questions for your team
Can your team search every build and developer laptop for all eight names? The Overlord loaders are tlxbnhd, tldriver and mxdriver. The stealer chain is native-runner, img-to-native and cdn-img-fetch. The downloader is function-flag, plus function-color, which installs it.
Checkmarx advises checking the resolved dependency tree and lockfiles. A malicious version can stay pinned after the registry removes it.
Does your registry proxy block the wrappers as well as the payload packages? Checkmarx says each wrapper needs its own block entry. Also purge private registries and caches. A takedown does not delete copies stored inside your network.
For a Windows host that installed one of these, Checkmarx advises isolating it. Treat it as compromised, even if node_modules was deleted. Change passwords from a clean system, end Telegram sessions and move crypto funds.
One check is easy to miss. The Overlord loader registers a scheduled task named \Maiden, backdated to 2020. It uses no registry Run keys, so a Run-key sweep finds nothing.
The lasting point is simple. A package missing from an advisory feed has not been cleared. It has only not been added to the feed yet, even where researchers have already published findings.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Checkmarx.





