Cybersecurity researchers have uncovered a long-running supply chain attack on npm that delivered information-stealing software and remote access tools to infected computers. The campaign, which security firms CloudSEK and Checkmarx have named MALFEX, appears to be the work of a single attacker who has posted 12 packages since August 2023, eight of which have been identified as malicious. The packages were collectively downloaded 40,767 times before being detected.
The malicious packages targeted Windows systems through three distinct infection routes, according to the report. One pathway loaded Overlord, an open-source remote access trojan written in Go that extracts its command-and-control server address from Solana blockchain transactions. A second chain installed movinlike, a Node.js-based stealer that harvests data from Discord, web browsers, Telegram, and cryptocurrency wallets. The third route functioned as a downloader. The eight flagged packages were tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, function-flag, function-color, and cdn-img-fetch, with the final three still live at the time of publication. Function-flag accounted for 37,419 downloads, making it responsible for more than 90 percent of the campaign's total reach. That package was first published in July 2024, with its most recent version released on August 4, 2025.
The report notes that the project description for one npm package contained a welcome message in Portuguese stating the project "was created with a lot of love and dedication by the Malfex team, whose owner is Murizada." Three packages—tlxbnhd, tldriver, and mxdriver—functioned as Overlord RAT loaders, with malicious code activated through lifecycle hooks that downloaded and executed Windows executables. Checkmarx researchers found that in the current version of function-color, "the postinstall script runs example.js, which calls the package's ASCII art function with the Bloody font," and that font selection "triggers a hidden routine" that downloads node.exe from a Brazilian application hosting service, saves it to the Windows AppData folder, and runs it with the window hidden. The function-color package contained no malicious payload itself but listed function-flag as a dependency, creating an indirect infection path.
The researchers traced the campaign to a Portuguese-speaking operator based on multiple indicators: git commits recorded at the -0300 time zone, one repository description written in Portuguese, and a GitHub display name and email address featuring a common Brazilian username. The Overlord RAT has appeared in at least two other attack campaigns since July 2026, including one exploiting WordPress vulnerabilities CVE-2026-63030 and CVE-2026-60137, and a macOS operation using a fake Zoom installer to deploy the trojan. That macOS campaign shares tactical similarities with a suspected North Korean threat group called UNK_DeadDrop. CloudSEK emphasized that the Portuguese-language evidence "is a piece of attribution to the operator's own linguistic space and nothing more," noting that delivery through npm and Discord is global and the second-stage targeting is opportunistic rather than geographically focused.
The report highlights the persistent risk of supply chain attacks that exploit developers' trust in open-source package repositories to distribute malware at scale. Each version of function-flag served its payload from a different remote location, demonstrating the attacker's efforts to evade detection through infrastructure rotation. The campaign's longevity—spanning more than two years—and the continued availability of three malicious packages underscore gaps in automated package vetting systems. Organizations relying on npm dependencies face mounting pressure to audit third-party code before integration, while repository maintainers confront the challenge of identifying malicious actors who blend in with legitimate publishers through seemingly benign package descriptions and incremental version updates.

