{"id":"MAL-2026-17663","summary":"Malicious code in mfasolver (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6f583d18816b977d3e721da8423405533e9915ad13631d8114e40e54aefd9152)\npackage.json at line 41 declares the only runtime dependency `node-net-pool` as `https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz` — an off-registry HTTP source pointing at the mutable `main` branch of a GitHub account unrelated to the mfasolver publisher, with no commit pin and no integrity hash. `npm install mfasolver` fetches whatever bytes that URL returns at install time and runs any lifecycle scripts contained in the fetched archive. The dependency is additionally force-loaded on require: `lib/cache.js` top-level calls `module['require']('node-net-pool')` inside a try/catch, so importing mfasolver also executes the attacker-controllable code. Separately, `index.js` opens TLS connections to discord.com with `rejectUnauthorized: false`, disabling certificate validation on the package's own Discord traffic.\n","modified":"2026-10-08T04:00:04.238808328Z","published":"2026-10-08T03:45:15Z","database_specific":{"malicious-packages-origins":[{"sha256":"6f583d18816b977d3e721da8423405533e9915ad13631d8114e40e54aefd9152","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021135","import_time":"2026-10-08T03:50:30.198048342Z","modified_time":"2026-10-08T03:45:15Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/mfasolver/v/1.0.0"}],"affected":[{"package":{"name":"mfasolver","ecosystem":"npm","purl":"pkg:npm/mfasolver"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfasolver/MAL-2026-17663.json","indicators":{"evidence_files":[{"tlsh":"1c217c26c8e82c5717c569e0ec198152b6721c070949bc1473ca86ad8f9e0bb22bf19e","path":"package.json","sha256":"9a2e278313d5b3de621650624f5f3cced6c9eccccc0a817e15d69294eb4d4534"},{"path":"index.js","sha256":"0e3494d24c490978c9e5e3d8b13e45fd261b6fac692f852045ff8b4241b3b63f","tlsh":"7a12621121f7203a0367d0ff9bd7d01567345903355ae9b8b78c9684afc361a85b3aee"}],"package_integrity":[{"filename":"mfasolver-1.0.0.tgz","hashes":{"sha1":"483447cc8b62e8513429f41918dc7c34221e4034","sha512_sri":"sha512-w5ICuAK1UhxTAhMBnfr8QEDWo6wWpSx7rfdRdPFhgjXfFdxLw0UPirEiBczbQ/KpBkRVYkqmpWEPp9Fn1kBuuA=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}