MAL-2026-15629
Malicious code in mfaatest (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (73e4ce261829117e316f9152160cdcb35c6ba66064f631baba1f8d528673b584) package.json declares dependency `node-net-pool` with its value set to an arbitrary HTTPS tarball URL (`https://limbomail.com/api/attachment/fpwvxc__9DvM.Bjuueu1K2SkBC_KkgATls-oq05UsrNNY/pkg.tgz`) rather than a registry version range. On `npm install`, npm fetches whatever bytes limbomail.com returns and installs them, executing any lifecycle scripts inside the fetched tarball. The source is unpinned, integrity-unchecked, and hosted on a domain unrelated to the package's stated publisher; the content can be swapped at any time by whoever controls that host. The package's own description claims 'zero runtime dependencies', contradicting the presence of this off-registry dependency and matching the smuggled-dropper shape.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for mfaatest (npm). Pin to a known-safe version or switch to an alternative.