The function-flag npm Supply Chain Attack (MALFEX)

Updated 7 Oct 2026 · Incident date 1 Jul 2024 · npm

Packagefunction-flag 2.3.4 -> 2.3.5
Fileexample.js

The npm package function-flag shipped malicious versions 2.3.5 through 2.3.9, 3.0.0, 4.0.0 and 1.7.3. Its first release, 2.3.4, was clean. Later releases added a postinstall script that downloads and runs a Windows program.

CloudSEK and Checkmarx Zero call the wider campaign MALFEX. Checkmarx counts eight malicious packages with 40,767 lifetime downloads. function-flag alone has 37,419.

What happened

One publisher group put eight malicious npm packages on the registry, and the packages reached real installs. Checkmarx Zero dates the operator's first npm activity to 6 August 2023.

The npm registry shows function-flag 2.3.4 published on 30 June 2024. Version 2.3.5 followed on 1 July 2024. Checkmarx lists 2.3.4 as not malicious and every later version as malicious. CloudSEK gives a different start. It says function-flag has been malicious since 18 July 2025, the day the registry shows 3.0.0 and 4.0.0 going out. The latest tag points to 1.7.3, published on 4 August 2025.

Checkmarx describes three delivery paths, all aimed at Windows:

  • function-flag downloader. A postinstall hook runs node example.js. It calls an ASCII art routine with the "Bloody" font, which triggers a hidden download to %APPDATA%\node.exe. The file runs with its window hidden. An empty catch hides any failure. Each version pulls its payload from a different address. The wrapper package function-color carries no payload and lists function-flag as a dependency.
  • Overlord RAT loaders. tlxbnhd, tldriver and mxdriver use preinstall and postinstall scripts. They download a file from api.imghippo.com, save it as gldriver_pre_core.exe and gldriver_pre_asset.exe, run it and delete it. The file is a Microsoft IExpress archive served as image/png. It holds a signed AutoIt3.exe and an encrypted script that decrypts Overlord, an open-source Go remote access tool.
  • Stealer chain. native-runner wraps img-to-native, which requires cdn-img-fetch. This path has no install hooks. Its code runs when the package loads. cdn-img-fetch downloads banner.png from GitHub. img-to-native decrypts data hidden after the image and writes %APPDATA%\Microsoft\Windows\node_runtime_helper.exe. That Go downloader fetches setup.exe from 104.234.65.75:700. Checkmarx names this 64 MB Node.js stealer movinlike.

Checkmarx says Overlord can capture the screen, log keys, read the clipboard, search files and open a remote shell. It reads its server address from encrypted Solana transaction memos. movinlike targets eight Discord clients, Chromium browsers, Telegram session data and crypto wallets. It sends the stolen data to a Discord webhook in 25 MB chunks.

Both CloudSEK and Checkmarx list five npm publisher accounts: malfexkkj, malfex_user, malfexteste2, malfexteste3 and malfexteste4. The registry lists jessica-fruett as the maintainer of function-flag. Checkmarx found the MALFEX name in the payload repo's git author email and in a README that credits the "MALFEX team" and names the owner as Murizada. CloudSEK links the payload host to the GitHub account cavecrew. Checkmarx found no widely used package that depends on these packages.

Affected versions

Checkmarx Zero lists these malicious versions, with lifetime downloads as of 1 October 2026:

PackageMalicious versionsDownloadsStatus on 29 Sep 2026
function-flag2.3.5 to 2.3.9, 3.0.0, 4.0.0, 1.7.337,419Live
function-color1.0.0, 1.7.3300Live
cdn-img-fetch1.0.0 to 1.0.3643Live
img-to-native1.0.0 to 1.0.3967Seized by npm
native-runner1.0.0 to 1.0.3872Seized by npm
tlxbnhd0.0.1139Unpublished
tldriver0.0.1138Unpublished
mxdriver0.0.1, 0.0.2289Unpublished

function-flag 2.3.4 is the only clean function-flag release. The OpenSSF records listed by Checkmarx are MAL-2026-16383, MAL-2026-16384, MAL-2026-16385, MAL-2026-17216, MAL-2026-17218 and MAL-2026-17320. Checkmarx says function-flag and function-color had no advisory.

Indicators of compromise

Checkmarx Zero published these indicators. Addresses appear here in plain form.

Download addresses

  • api.imghippo.com/files/hOG8244hc.png (Overlord loader)
  • raw.githubusercontent.com/cavecrew/proj/main/banner.png (stealer chain)
  • raw.githubusercontent.com/cavecrew/proj/main/banner.jpg (cdn-img-fetch 1.0.3)
  • 104.234.65.75:700/setup.exe and 104.234.65.75/setup.exe (movinlike)
  • cdnzona.discloud.app/node.exe (function-flag 1.7.3)
  • apicdn.squareweb.app (function-flag 4.0.0)
  • bypasscdn.onrender.com (function-flag 3.0.0)
  • 45.89.30.194 (function-flag 2.3.8 and 2.3.9)
  • 191.96.81.101 (function-flag 2.3.7)
  • apizona.onrender.com (function-flag 2.3.6)
  • 51.137.158.178/download (function-flag 2.3.5)
  • www.image.com (mxdriver)

Files and persistence on Windows

  • %LOCALAPPDATA%\ScopeSmart Technologies Inc\ with AutoIt3.exe, h.a3x and SmartScope.vbs
  • Scheduled task \Maiden, which runs AutoIt3.exe every 5 minutes
  • gldriver_pre_core.exe and gldriver_pre_asset.exe in the package folder
  • %APPDATA%\Microsoft\Windows\node_runtime_helper.exe
  • %TEMP%\._cif_data
  • %APPDATA%\node.exe

SHA256 hashes

  • Overlord loader served as PNG: 9aba4685af072231aee049e1a5e294965580001b364d7d00152d84fcec1ce793
  • AutoIt3.exe from the archive: 5d69a932a077fee044b193c28e84564143f5c7e51079ab48e88fef74ab0b77b7
  • Oxygen.a3x / h.a3x: fd199d3977e1a2945b6031fc8696660a980e4f4617899baa045efe7ccbc8de67
  • Overlord, decoded: 2989244eac2a4bc7a13a09dec003e5c05ef7c80b2afe0958ce25042d5b804210
  • banner.png: 4f4f7d64139bde6d458a061c7fb7dd247f70f60a1ab47d87fd3634656586c106
  • Stealer chain downloader: 889e13e227bc2b762178b88c35c691db3256e72be64d92ff1f381d29a2789849
  • Stealer chain downloader: e7f86f6cc4380db66d333eaf6f7dfc2c12d232c2bcd526434681245dea25efa4
  • Stealer chain downloader: ff826d2778ea1d40ce8ebfd9d66ecc86d4c811f5654b8a466a7e220ebbbc6807
  • Stealer chain downloader: 2f268ca76ab27971d8b16bd4ded26e1f9cd3d4460b894af2d4bdf89f0ab7ec4b
  • tlxbnhd postinstall.js: 7acf331117900179b483142f216fdcb22c671eb0b1971abd57f01bc036248a6e
  • movinlike: c9c374afba4658dff15f71801e88c4d199c91dd2622d72c7b0c55577c8f73437

How to check

Run this command in each project folder to list any of the eight packages, including deep dependencies:

npm ls function-flag function-color cdn-img-fetch img-to-native native-runner tlxbnhd tldriver mxdriver --all

Search your lockfiles for the same names. This also covers pnpm and Yarn projects:

grep -rlE "function-flag|function-color|cdn-img-fetch|img-to-native|native-runner|tlxbnhd|tldriver|mxdriver" --include=package-lock.json --include=npm-shrinkwrap.json --include=pnpm-lock.yaml --include=yarn.lock .

On a Windows machine that installed one of them, look for the scheduled task that Checkmarx describes:

schtasks /query /tn "\Maiden" /fo LIST /v

Then check that the ScopeSmart folder, node_runtime_helper.exe and %APPDATA%\node.exe are absent. Checkmarx says the function-flag payload fails silently outside Windows because APPDATA is not set.

What to do now

  1. If a Windows machine installed any of these packages, isolate it. Keep its logs and files as evidence. Checkmarx says to treat it as compromised even after you delete node_modules.
  2. Delete the \Maiden task, the ScopeSmart folder, node_runtime_helper.exe and %APPDATA%\node.exe. Keep a forensic copy first.
  3. From a clean machine, change the passwords for Discord, browser-saved accounts and other accounts used on that host.
  4. End all Telegram sessions. Move crypto funds to new wallets.
  5. Look for unexpected Discord payments and unfamiliar sign-ins on your other accounts.
  6. Block all eight packages at your registry proxy, including the wrappers function-color and native-runner.
  7. Purge the packages from private registries, proxies and caches.
  8. Block the download addresses above. Null-route 104.234.65.75. Checkmarx advises against blocking all of discord.com or raw.githubusercontent.com.
  9. Do not rely on --ignore-scripts alone. The stealer chain runs when the package loads, not at install.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old function-flag-2.3.4 --new function-flag-2.3.5
files scanned: 43 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   example.js
           It runs a command on its own when it is installed, downloads from the internet and runs other programs.

Frequently asked questions

What is the MALFEX npm campaign?

MALFEX is the name CloudSEK and Checkmarx gave to eight malicious npm packages, led by function-flag. They download Windows stealers and the Overlord remote access tool.

Which function-flag versions are malicious?

Checkmarx lists 2.3.5 through 2.3.9, 3.0.0, 4.0.0 and 1.7.3 as malicious. Version 2.3.4 is clean.

Does function-flag affect macOS or Linux?

Checkmarx says the function-flag payload fails silently outside Windows because the APPDATA variable is not set. All payloads in the campaign are Windows programs.

Is --ignore-scripts enough to stay safe?

No. The stealer chain in img-to-native and cdn-img-fetch runs when the package loads, so it needs no install script.

Sources

  1. checkmarx.com/zero-post/malfex-npm-malware-campaign-three-payloads-and-an-adversary-that-signs-their-work/
  2. cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
  3. registry.npmjs.org/function-flag

More supply chain attacks

All 113 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free