MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months

Summary
CloudSek links a set of malicious npm packages to one operator and two delivery arms, including active packages that remained available after a related package was seized. The campaign steals credentials and data from Windows systems.
Key points
- The report links at least 12 npm packages and a GitHub payload repository to one operator; some packages were malicious while others served as cover.
- Three packages lacked advisories: function-flag, cdn-img-fetch, and function-color. The report says they were still active or installable at the time of writing.
- One delivery arm uses npm packages to install an AutoIt-based loader and the Overlord Go RAT, with a live Solana-based command-and-control resolver in the recovered build.
- A second arm retrieves an encrypted payload from GitHub and downloads a Node.js bundle that injects into Discord clients, collects browser and Telegram data, and exfiltrates it through a Discord webhook.
- Amazon Inspector advisories covered five packages, but the report says cdn-img-fetch remained reachable after npm seized its parent package, img-to-native.
- Recommended defenses include blocking the three unadvised packages, monitoring specified persistence artifacts, restricting outbound access to identified payload hosts and the webhook, and reviewing dependencies during package takedowns.
Article Details
- Attack Vectors
- The operator published malicious npm packages that execute during postinstall. function-color also pulls in the malicious function-flag package as a dependency.
- Delivery Arm A downloads a Windows executable disguised as image/png, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and an encrypted script, and executes an overlord-client build.
- Delivery Arm B retrieves a PNG polyglot from a GitHub repository, decrypts an embedded payload using the malfexteam2027 key, and fetches the movinlike Node.js bundle. The bundle injects into Discord clients, harvests browser and Telegram tdata, and exfiltrates data to a Discord webhook.
- Defensive Notes
- Block installation of function-flag, cdn-img-fetch, and function-color.
- Alert on %LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe and the \Maiden scheduled task.
- Restrict outbound connections to the identified payload hosts and Discord webhook.
- Inspect declared dependencies when taking down a registry package; cdn-img-fetch remained installable after npm seized its parent package, img-to-native.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | api[.]imghippo[.]com | Image-host endpoint identified as hosting the Delivery Arm A payload. |
| IPV4 | 104[.]234[.]65[.]75 | Host at port 700 from which Delivery Arm B fetches the movinlike Node.js bundle. |
MITRE ATT&CK
T1053.005 · Scheduled TaskThe report identifies a \Maiden scheduled task as a persistence artifact.T1055 · Process InjectionThe movinlike bundle injects into Discord clients.T1105 · Ingress Tool TransferThe package delivery chains download additional payloads, including a disguised Windows executable and the movinlike Node.js bundle.T1140 · Deobfuscate/Decode Files or InformationDelivery Arm B decrypts an embedded payload from a PNG polyglot using the malfexteam2027 key.T1195.001 · Compromise Software Dependencies and Development ToolsThe operator published malicious npm packages, including postinstall packages and a wrapper that pulls in a malicious dependency.T1567 · Exfiltration Over Web ServiceThe movinlike bundle exfiltrates stolen data to a Discord webhook.
Threat Actors
Malware
movinlikedecrypts an embedded payload using the malfexteam2027 key, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700 that injects into Discord clients, harvests browser and Telegram tdata, andOverlordIExpress cabinet containing a signed AutoIt3 interpreter and encrypted script, and executes a build of overlord-client (an open-source Go RAT described by Jamf Threat Labs in August 2026). This recovered buildoverlord-clientcabinet containing a signed AutoIt3 interpreter and encrypted script, and executes a build of overlord-client (an open-source Go RAT described by Jamf Threat Labs in August 2026). This recovered build includes a
Vendors
Discordkey, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700 that injects into Discord clients, harvests browser and Telegram tdata, and exfiltrates stolen data to an active Discord webhook.GitHubunder Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools thenpm2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but
Products
AutoIt3disguised as image/png from a public image host, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and encrypted script, and executes a build of overlord-client (an open-source Go RATDiscordkey, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700 that injects into Discord clients, harvests browser and Telegram tdata, and exfiltrates stolen data to an active Discord webhook.GitHubunder Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools theIExpresspackages) downloads a Windows PE executable disguised as image/png from a public image host, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and encrypted script, and executes a build ofNode.jsdecrypts an embedded payload using the malfexteam2027 key, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700 that injects into Discord clients, harvests browser andnpm2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious butSolanaby Jamf Threat Labs in August 2026). This recovered build includes a previously undocumented live Solana blockchain C2 resolver. Delivery Arm B (two packages, one active) retrieves a PNG polyglot from