A persistent npm supply-chain campaign dubbed MALFEX has distributed Windows malware through eight malicious packages, accumulating 40,767 downloads by October 1, 2026 — including 3,017 in the final week alone — according to a technical analysis by Checkmarx. Three of the packages were still live and installable at the time of research, two of them with no security advisory at all.

The campaign is attributed by Checkmarx to what appears to be a single operator publishing to the registry since August 6, 2023 — twelve packages in total, eight malicious and four benign cover packages. The attribution is the vendor's assessment, not a law-enforcement finding.

Three delivery paths, three payloads

The first chain runs through tlxbnhd, tldriver and mxdriver, whose obfuscated preinstall and postinstall scripts pull a Windows executable disguised as a PNG from an image-hosting service. The file is an IExpress archive containing a legitimately signed AutoIt interpreter and an encrypted script that decodes through successive XOR, RC4 and LZNT1 stages into the open-source Overlord remote access trojan. Persistence comes from a scheduled task named "Maiden" running every five minutes. Code analysis indicated process hollowing into TapiUnattend.exe, though researchers did not observe the injection at runtime. Overlord supports keylogging, screen and clipboard capture, remote shells and hidden-desktop access, and can resolve command-and-control servers through encrypted Solana transaction memos — though the analyzed build contained no configured C2 addresses.

The second chain — native-runner, img-to-native and cdn-img-fetch — executes malicious code when the package loads rather than at install time. It fetches a GitHub-hosted PNG with an encrypted executable appended after the image data, decrypted with the key malfexteam2027. The resulting Go downloader retrieves movinlike, a 64 MB Node.js information stealer targeting eight Discord clients, browser cookies and saved passwords, Telegram Desktop sessions, and cryptocurrency wallets including MetaMask, Phantom and Coinbase Wallet. Stolen files are compressed, split into 25 MB chunks and exfiltrated through a Discord webhook.

The third path is the oldest: function-flag, malicious since July 2025 and responsible for 37,419 of the campaign's recorded downloads. Its postinstall script invokes an ASCII-art function with the "Bloody" font as cover for a concealed download of node.exe; the download host was unresponsive during analysis and that final payload remains unrecovered.

The advisory gap

What makes MALFEX notable for defenders is the state of advisory coverage. Five packages were unpublished or seized by npm and carry OSV malware advisories. But as of September 29, function-flag and function-color had no advisory at all, and the advisory for cdn-img-fetch (MAL-2026-17320, published September 30) lists only versions 1.0.0 and 1.0.1, omitting the malicious 1.0.2 and 1.0.3. Download counts measure registry activity, not confirmed infections — but tooling that relies solely on advisory feeds will miss affected dependencies, a point both Checkmarx and GBHackers' reporting emphasize.

Checkmarx's recommended response: block all eight packages, and treat any Windows system that installed them as compromised — isolate the host, remove persistence (checking scheduled tasks specifically, since the Overlord loader avoids registry Run keys), and rotate credentials and seed phrases from a clean device.

For crypto teams, MALFEX is a reminder that wallet compromise increasingly begins in the dependency tree, not the browser. A single malicious postinstall script on a developer machine can reach browser extension wallets, hardware-wallet companion apps and CI credentials alike; the supply chain is the attack surface.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.