Back
Adversary Intelligence
Table of Content
Vikas Kundu
A naturally curious mind driven by the need to understand how things work and how to make them better. Passionate about learning, experimenting, and exploring new ideas across technology and security.
No items found.

Executive Summary

Between August 2023 and September 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools the operator ships as cover. The three packages without advisories are the only active threats defenders can target today: function-flag (continuously malicious since 18 July 2025), cdn-img-fetch (still installable after npm seized its parent package, img-to-native), and function-color (a wrapper that pulls function-flag in as a dependency). While individual advisories issued by the ecosystem are accurate, they overlook that these are not three separate dropper incidents; they form a single operator supply chain operating via two delivery arms, with one arm remaining active despite partial seizures.

The operator identifies themselves directly within the malware, and as of 28 September 2026, an official advisory reflects this. Amazon Inspector's OSV entry MAL-2026-17216 for img-to-native identifies malfexteam2027 as a hardcoded key-derivation constant and names cdn-img-fetch as a companion dependency, though it failed to link the key to a specific operator or note that cdn-img-fetch remained accessible. The malfex naming root appears across five npm publisher handles (malfexkkj, malfex_user, malfexteste2, malfexteste3, malfexteste4), the payload repository's git author email ([email protected]), and the README for [email protected] ("criado pela equipe Malfex, cujo dono Ă© Murizada"). 

The GitHub account behind the payload host (cavecrew, display name muriel, commits at -0300) publicly shares the campaign's two main techniques: a Windows credential stealer and a process-hollowing proof of concept. Delivery Arm A (three co-advised packages) downloads a Windows PE executable disguised as image/png from a public image host, extracts an IExpress cabinet containing a signed AutoIt3 interpreter and encrypted script, and executes a build of overlord-client (an open-source Go RAT described by Jamf Threat Labs in August 2026). This recovered build includes a previously undocumented live Solana blockchain C2 resolver. Delivery Arm B (two packages, one active) retrieves a PNG polyglot from raw.githubusercontent.com/cavecrew/proj, decrypts an embedded payload using the malfexteam2027 key, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700 that injects into Discord clients, harvests browser and Telegram tdata, and exfiltrates stolen data to an active Discord webhook.

Defenders can mitigate the threat quickly: block installation of function-flag, cdn-img-fetch, and function-color; alert on persistence artifacts like %LOCALAPPDATA%\ScopeSmart Technologies Inc\AutoIt3.exe and the \Maiden scheduled task; restrict outbound connections to payload hosts and the specified Discord webhook; and inspect all declared dependencies whenever taking down a registry package to prevent active components from remaining online.

What is new in this report

Five of the eight MALFEX packages carry OSV advisories issued by Amazon Inspector between 22 and 28 September 2026. Those advisories cover the Arm A dropper trio (tlxbnhd, tldriver, mxdriver), the img-to-native decryptor, the shared api.imghippo.com payload URL, the dropped filenames gldriver_pre_core.exe and gldriver_pre_asset.exe, the cross-platform launch commands, and, in the img-to-native entry, the malfexteam2027 key string and the cdn-img-fetch dependency by name. 

Overlord is an open-source Go RAT documented in detail by Jamf Threat Labs on 6 August 2026 as a fake-Zoom-installer campaign against macOS, and by third-party threat-intelligence pages before that. 

What this report adds is the operator behind the advised parts and the parts they left reachable. Specifically: that the malfexteam2027 key is the operator’s own team name, attested word-for-word in the README of [email protected], and that the same operator runs a public GitHub account (cavecrew, git email [email protected]) publishing the two techniques the campaign uses; that function-flag has been an unadvised malicious postinstall for fourteen months; that cdn-img-fetch, named in the img-to-native advisory as a dependency, remains reachable on the registry after its parent was seized; that the loader chain leading to Overlord is a Microsoft IExpress cabinet over a signed AutoIt3 interpreter over an EA06 encrypted a3x over cycled-XOR strings, RC4 key 8448433, and LZNT1; that the Solana-memo C2 channel Jamf described as “present but disabled” is wired into this build as live literal strings, giving the first observed sample where the mechanism is actually available; that Overlord is here delivered by an npm supply-chain vector for which Jamf's writeup explicitly reported “initial delivery vector still under investigation”; and that Arm B’s second stage is a distinct Node.js stealer, movinlike, whose Discord webhook is live at the time of writing. The two-year operator continuity, the identity synthesis across eight accounts, and the takedown‐vs‐dependency gap on the seizure of img-to-native are the report’s own contribution.

Click Here To Read Full Report

Related Blogs