MALFEX – A malicious npm postinstall no advisory has caught for fourteen months

MALFEX – A malicious npm postinstall no advisory has caught for fourteen months
A single operator using Portuguese-language aliases ran a long-lived npm and GitHub supply chain that delivered malicious packages, payloads, and stealers through two delivery arms, including the active packages function-flag and cdn-img-fetch. The campaign is tied to the team string malfexteam2027, the GitHub account cavecrew, and payloads such as Overlord and movinlike, with active infrastructure including a Discord webhook and 104.234.65.75:700. #malfexteam2027 #cavecrew #function-flag #cdn-img-fetch #Overlord #movinlike

Keypoints

  • At least nine npm packages and one GitHub payload repository were uploaded by a single operator between August 2023 and September 2026.
  • The most important active threats are function-flag, which has remained malicious since 18 July 2025, and cdn-img-fetch, which remains installable even after its parent package was seized.
  • The operator is directly identified by the string malfexteam2027, which appears across npm publisher handles, GitHub metadata, and README text.
  • Delivery Arm A used public image-hosted content, IExpress, signed AutoIt3, encrypted scripts, and a recovered build of Overlord with a live Solana blockchain C2 resolver.
  • Delivery Arm B used a PNG polyglot from GitHub, a decryption key, a 64 MB Node.js bundle named movinlike, and a live Discord webhook to steal browser, Telegram, and Discord data.
  • Amazon Inspector advisories covered several packages and artifacts, but missed the broader single-operator supply-chain structure and the continued availability of active components.
  • Defenders are advised to block function-flag and cdn-img-fetch, watch for persistence artifacts, and inspect dependencies when taking down registry packages.

MITRE Techniques

  • [T1195.001 ] Compromise Software Dependencies and Development Tools – The operator abused npm packages and dependency wrappers to deliver payloads through the software supply chain (‘uploaded at least nine packages to npm’ and ‘dependency wrappers that deliver an existing payload under a new install name’).
  • [T1204.002 ] User Execution: Malicious File – The campaign relied on installs and execution paths that trigger payloads during package installation (‘postinstall’ and ‘executes a build of overlord-client’).
  • [T1105 ] Ingress Tool Transfer – Payloads were retrieved from external infrastructure and public hosts (‘downloads a Windows PE executable disguised as image/png’ and ‘fetches a 64 MB Node.js bundle from 104.234.65.75:700’).
  • [T1027 ] Obfuscated Files or Information – The payload chain used encryption, polyglots, and encoded loaders to hide content (‘PNG polyglot’, ‘encrypted payload’, ‘EA06 encrypted a3x’, ‘cycled-XOR strings, RC4 key 8448433, and LZNT1’).
  • [T1218.010 ] System Binary Proxy Execution: AutoIt – A signed AutoIt3 interpreter was used to run the malicious script (‘extracts an IExpress cabinet containing a signed AutoIt3 interpreter and encrypted script’).
  • [T1564.001 ] Hide Artifacts: Hidden Files and Directories – The malware dropped executable files with innocuous-looking names and used masquerading to blend in (‘disguised as image/png’ and ‘dropped filenames gldriver_pre_core.exe and gldriver_pre_asset.exe’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Persistence artifacts included a Windows scheduled task (‘the Maiden scheduled task’).
  • [T1036 ] Masquerading – The malicious executable was presented as benign content or leveraged trusted-looking names (‘disguised as image/png’ and ‘benign reputation cover’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – Command-and-control and data retrieval used web-based services and webhook traffic (‘raw.githubusercontent.com/cavecrew/proj’ and ‘Discord webhook’).
  • [T1056.001 ] Input Capture: Keylogging – The report describes a Windows credential stealer and browser/Telegram harvesting behavior (‘a Windows credential stealer’ and ‘harvests browser and Telegram tdata’).
  • [T1055 ] Process Injection – The report states that the payload injects into Discord clients (‘injects into Discord clients’).
  • [T1021.004 ] Remote Services: SSH/SMB? – Not mentioned; omitted.

Indicators of Compromise

  • [Domains/URLs ] Payload hosting and source locations – api.imghippo.com, raw.githubusercontent.com/cavecrew/proj
  • [IP address ] Command-and-control / payload retrieval endpoint – 104.234.65.75:700
  • [File names ] Malicious packages and payloads – function-flag, cdn-img-fetch, img-to-native, movinlike
  • [File names ] Dropped and referenced executables/scripts – gldriver_pre_core.exe, gldriver_pre_asset.exe
  • [Windows paths ] Persistence and install artifacts – %LOCALAPPDATA%ScopeSmart Technologies IncAutoIt3.exe, Maiden scheduled task
  • [Hashes / keys ] Embedded decryption or derivation string – malfexteam2027, RC4 key 8448433
  • [GitHub identifiers ] Public operator infrastructure – cavecrew, [email protected]
  • [Webhook ] Exfiltration target – active Discord webhook


Read more: https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign