Security1 publisher2 min readPublished
Checkmarx finds malicious npm package function-flag still installable after 37,000 downloads
Checkmarx says function-flag, malicious since July 2025 and downloaded more than 37,000 times, is still on npm with no advisory flagging it. Advisory-based scanners have nothing to match, so finding it means checking lockfiles for the campaign's eight names.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The operator behind MALFEX has published 12 npm packages since August 2023, eight of them malicious, with more than 40,000 downloads between them.
- Open Source Vulnerabilities (OSV) has published advisories for six of the eight malicious packages.
- Checkmarx traced three delivery paths with no shared infrastructure between them, all tied to the same actor.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Teams relying on advisory feeds get no alert for function-flag, and OSV-based tools miss function-color too, so detection depends on matching package names directly.
- constraint A blocklist entry for one function-flag payload host protects against a single release, since each version pulls from its own location.
- exposure Windows hosts with a direct install are the exposed population, and the documented payloads hand the operator keystrokes, a remote shell and browser and wallet data.
- decision With no legitimate package depending on these names, a dependency tree that lacks a direct install of all eight needs no further work for this campaign.
The five packages already removed from the registry all have OSV entries [18]. The gaps are on the three still live. Function-flag and function-color are not on the OSV list, and the cdn-img-fetch entry covers two of that package's four malicious versions [16][8]. Function-flag accounts for about nine-tenths of the campaign's reported downloads [17].
According to Checkmarx, function-flag is the campaign's longest-running delivery path [13]. Each malicious version ships its own downloader, and each downloader fetches its payload from a different location [13]. Blocking one payload host covers one release [20]. The install finishes even when the download fails [14]. On macOS and Linux the routine fails silently, so only Windows machines get a working payload [14].
The other two paths run at different stages. The first runs obfuscated scripts during npm install on Windows, macOS and Linux, though its Overlord RAT payload works only on Windows [10]. Overlord gives the operator screen capture, keylogging, window monitoring, a remote shell, file search and a hidden desktop [11]. The second path runs when the package is loaded and drops movinlike, a Node.js stealer aimed at eight Discord clients, seven browsers and cryptocurrency wallets [12]. Turning off install scripts addresses the first path and leaves the second untouched [19].
One operator has run MALFEX, Checkmarx's name for the campaign, since August 2023 [2][3]. Its three paths share no infrastructure [9]. Checkmarx describes the reach as narrow and untargeted. "No legitimate or widely used packages depend on any operator package, so exposure is limited to systems that installed these package names directly. We found no geographic or organizational targeting; anyone who installs the stealer becomes a target," Checkmarx wrote [15].
The eight malicious names are tlxbnhd, tldriver, mxdriver, img-to-native, native-runner, cdn-img-fetch, function-flag and function-color [7][5]. A scanner that matches dependencies against advisories has no entry for function-flag. A name search across lockfiles and install logs will find it [21]. The Windows-only limit is reported for the Overlord payload and for function-flag, not for movinlike [10][14][12].
What to watch
- Whether the registry pulls function-flag, function-color and cdn-img-fetch, and whether OSV adds function-flag and function-color and extends the cdn-img-fetch entry to all four malicious versions.
- A new function-flag release; each version so far has carried its own downloader and payload location, so a fresh publish would show the operator still working that path.
- Any report of a legitimate package taking a dependency on one of the operator's packages, since that would extend exposure past direct installs.