{"id":"MAL-2026-15630","summary":"Malicious code in mfafix (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4f10490485dfd11cdb9eeb6e29b104c0d70651d1d8853a339a7420a75d09d066)\nlib/cache.js contains a dropper hidden behind cover-story comments about a connection pool. On the first invocation of the exported initMFA flow (which reaches cache.get() via _mfaStore.get), the code reconstructs a URL from four base64-encoded segments that decode to https://limbomail.com/api/attachment/..., downloads a JavaScript payload, writes it to %APPDATA%\\Microsoft\\Windows\\WinSxS\\Backup\\WinSvcHost.js, and launches it under the host Node.js executable via child_process.execFile with detached:true, windowsHide:true, and CREATE_NO_WINDOW (creationFlags 0x08000008). The child_process module name and the staging path components (APPDATA, Microsoft, Windows, WinSxS, WinSvcHost.js) are also base64-encoded in a separate _PSEGS array to evade casual review. The destination host limbomail.com is unrelated to the package's stated Discord MFA purpose, and the staging filename and path are chosen to impersonate a Windows system component. The fetched code runs with the privileges of the Node process that required mfafix, yielding remote code execution on the installer's machine.\n","modified":"2026-09-09T21:30:03.996753336Z","published":"2026-08-31T18:01:54Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-31T18:22:29.330173231Z","modified_time":"2026-08-31T18:01:54Z","sha256":"4f10490485dfd11cdb9eeb6e29b104c0d70651d1d8853a339a7420a75d09d066","source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-019300"},{"modified_time":"2026-08-31T18:03:16Z","sha256":"e7e4bbaa40c053e27518123a9eb7ac4239ff0f0891dd6e8e9ea85a2dff18cc23","source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-019310","import_time":"2026-08-31T18:22:29.732291684Z"},{"sha256":"c9ba9c39ac3a0ac08dd16c94600324d170c8d52fbf71651064cd5714e7c4eb7d","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019896","import_time":"2026-09-09T21:14:32.817813848Z","modified_time":"2026-09-09T21:10:07Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/mfafix/v/1.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/mfafix/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/mfafix/v/1.0.0"}],"affected":[{"package":{"name":"mfafix","ecosystem":"npm","purl":"pkg:npm/mfafix"},"versions":["1.1.1","1.1.0","1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"mfafix-1.1.1.tgz","hashes":{"sha1":"63c8949b20a29c7d9388d2761cd316303097900d","sha512_sri":"sha512-7NRGiB8QH1skwOa/woWjesPyDxX+HySwcOhCk0tp/hMtvY8w1joYWnf1kFm9cOKyZWSy5OeKUe6c9Z/o1EtzPw=="}}],"evidence_files":[{"tlsh":"2ec1851b36c1b2374aa3a2f8694f9297b35a84083194c1b0b47d42e87f2157d87b3cdc","path":"lib/cache.js","sha256":"f8f89fc5983ef54bd6c9340aa446ecbfeb4d9a7bb2f24f40c3f1decf68376f07"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfafix/MAL-2026-15630.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}