A single operator using Portuguese-language aliases ran a long-lived npm and GitHub supply chain that delivered malicious packages, payloads, and stealers through two delivery arms, including the active packages function-flag and cdn-img-fetch. The campaign is tied to the team string malfexteam2027, the GitHub account cavecrew, and payloads such as Overlord and movinlike, with active infrastructure including a Discord webhook and 104.234.65.75:700. #malfexteam2027 #cavecrew #function-flag #cdn-img-fetch #Overlord #movinlike
Keypoints
- At least nine npm packages and one GitHub payload repository were uploaded by a single operator between August 2023 and September 2026.
- The most important active threats are function-flag, which has remained malicious since 18 July 2025, and cdn-img-fetch, which remains installable even after its parent package was seized.
- The operator is directly identified by the string malfexteam2027, which appears across npm publisher handles, GitHub metadata, and README text.
- Delivery Arm A used public image-hosted content, IExpress, signed AutoIt3, encrypted scripts, and a recovered build of Overlord with a live Solana blockchain C2 resolver.
- Delivery Arm B used a PNG polyglot from GitHub, a decryption key, a 64 MB Node.js bundle named movinlike, and a live Discord webhook to steal browser, Telegram, and Discord data.
- Amazon Inspector advisories covered several packages and artifacts, but missed the broader single-operator supply-chain structure and the continued availability of active components.
- Defenders are advised to block function-flag and cdn-img-fetch, watch for persistence artifacts, and inspect dependencies when taking down registry packages.
MITRE Techniques
- [T1195.001 ] Compromise Software Dependencies and Development Tools â The operator abused npm packages and dependency wrappers to deliver payloads through the software supply chain (âuploaded at least nine packages to npmâ and âdependency wrappers that deliver an existing payload under a new install nameâ).
- [T1204.002 ] User Execution: Malicious File â The campaign relied on installs and execution paths that trigger payloads during package installation (âpostinstallâ and âexecutes a build of overlord-clientâ).
- [T1105 ] Ingress Tool Transfer â Payloads were retrieved from external infrastructure and public hosts (âdownloads a Windows PE executable disguised as image/pngâ and âfetches a 64 MB Node.js bundle from 104.234.65.75:700â).
- [T1027 ] Obfuscated Files or Information â The payload chain used encryption, polyglots, and encoded loaders to hide content (âPNG polyglotâ, âencrypted payloadâ, âEA06 encrypted a3xâ, âcycled-XOR strings, RC4 key 8448433, and LZNT1â).
- [T1218.010 ] System Binary Proxy Execution: AutoIt â A signed AutoIt3 interpreter was used to run the malicious script (âextracts an IExpress cabinet containing a signed AutoIt3 interpreter and encrypted scriptâ).
- [T1564.001 ] Hide Artifacts: Hidden Files and Directories â The malware dropped executable files with innocuous-looking names and used masquerading to blend in (âdisguised as image/pngâ and âdropped filenames gldriver_pre_core.exe and gldriver_pre_asset.exeâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Persistence artifacts included a Windows scheduled task (âthe Maiden scheduled taskâ).
- [T1036 ] Masquerading â The malicious executable was presented as benign content or leveraged trusted-looking names (âdisguised as image/pngâ and âbenign reputation coverâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â Command-and-control and data retrieval used web-based services and webhook traffic (âraw.githubusercontent.com/cavecrew/projâ and âDiscord webhookâ).
- [T1056.001 ] Input Capture: Keylogging â The report describes a Windows credential stealer and browser/Telegram harvesting behavior (âa Windows credential stealerâ and âharvests browser and Telegram tdataâ).
- [T1055 ] Process Injection â The report states that the payload injects into Discord clients (âinjects into Discord clientsâ).
- [T1021.004 ] Remote Services: SSH/SMB? â Not mentioned; omitted.
Indicators of Compromise
- [Domains/URLs ] Payload hosting and source locations â api.imghippo.com, raw.githubusercontent.com/cavecrew/proj
- [IP address ] Command-and-control / payload retrieval endpoint â 104.234.65.75:700
- [File names ] Malicious packages and payloads â function-flag, cdn-img-fetch, img-to-native, movinlike
- [File names ] Dropped and referenced executables/scripts â gldriver_pre_core.exe, gldriver_pre_asset.exe
- [Windows paths ] Persistence and install artifacts â %LOCALAPPDATA%ScopeSmart Technologies IncAutoIt3.exe, Maiden scheduled task
- [Hashes / keys ] Embedded decryption or derivation string â malfexteam2027, RC4 key 8448433
- [GitHub identifiers ] Public operator infrastructure â cavecrew, [email protected]
- [Webhook ] Exfiltration target â active Discord webhook
Read more: https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign