CloudSEK and Checkmarx detailed MALFEX, a campaign they attribute to a lone actor who has published eight malicious npm packages downloaded 40,767 times in total, with function-flag alone accounting for 37,419. The Windows-focused packages deliver three payloads: Overlord, an open-source Go remote access trojan that pulls its command-and-control address from Solana transactions; a Node.js stealer that targets Discord, browsers, Telegram, and cryptocurrency wallets; and a downloader. Lifecycle and postinstall hooks fetch and run remote executables, with one package saving a hidden node.exe to the AppData directory. Three packages, function-flag, function-color, and cdn-img-fetch, were still live on npm at publication.