Three npm Records Remain Queryable
Three npm records tied to MALFEX remain queryable while official advisory coverage is incomplete. On 6 October, function-flag and function-color resolved latest to 1.7.3. cdn-img-fetch resolved to 1.0.4, which Checkmarx does not classify as malicious.
Eight packages
Checkmarx identifies function-flag, function-color, cdn-img-fetch, img-to-native, native-runner, tlxbnhd, tldriver and mxdriver. It labels the latest 1.7.3 releases of function-flag and function-color malicious. Its version table, which does not classify cdn-img-fetch 1.0.4 as malicious, should guide blocking and hunting.
Official OSV queries returned no record for function-flag or function-color. MAL-2026-17320 covers only cdn-img-fetch 1.0.0 and 1.0.1. Advisory-only checks can therefore miss packages.
Execution
On Windows, install hooks delivered a RAT or downloader; another stealer chain ran when loaded. --ignore-scripts does not stop load-time execution.
Response
Search dependencies and lockfiles for all eight names. Checkmarx advises isolating affected Windows hosts and rotating exposed credentials from a clean system. Block specific malicious paths, not GitHub or Discord wholesale.
Limits
Availability does not prove infection or a live payload. Exposure was through direct installs or wrappers. Current payload endpoints were not checked. No CVE is assigned.
Related: separate npm runtime case.


