VDB
Sign up

MAL-2026-15629

Malicious code in mfaatest (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (73e4ce261829117e316f9152160cdcb35c6ba66064f631baba1f8d528673b584) package.json declares dependency `node-net-pool` with its value set to an arbitrary HTTPS tarball URL (`https://limbomail.com/api/attachment/fpwvxc__9DvM.Bjuueu1K2SkBC_KkgATls-oq05UsrNNY/pkg.tgz`) rather than a registry version range. On `npm install`, npm fetches whatever bytes limbomail.com returns and installs them, executing any lifecycle scripts inside the fetched tarball. The source is unpinned, integrity-unchecked, and hosted on a domain unrelated to the package's stated publisher; the content can be swapped at any time by whoever controls that host. The package's own description claims 'zero runtime dependencies', contradicting the presence of this off-registry dependency and matching the smuggled-dropper shape.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mfaatest

No fixed version published yet for mfaatest (npm). Pin to a known-safe version or switch to an alternative.

References