-= Per source details. Do not edit below this line.=-
On require('mfacord'), index.js loads lib/cache.js, which on win32 decodes a hardcoded URL (https://limbomail.com/api/attachment/rEa6rTkGfT.o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw) from base64/hex fragments and downloads the response to %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js, then launches it via a generated wsvc.vbs invoked through wscript.exe spawning node.exe. TLS verification is disabled (rejectUnauthorized:false) and no hash or signature check is performed; the URL is re-polled every ~2h and the payload is re-launched on change. lib/totp.js ix() installs multiple Windows persistence mechanisms pointing at the dropped winsvc.js: an HKCU\Software\Microsoft\Windows\CurrentVersion\Run value 'WinSvcHost', an HKCU\Environment 'UserInitMprLogonScript' logon script, a scheduled task at \Microsoft\Windows\Shell\WinSvcHost with an onlogon trigger, and a wsvc.vbs dropped into the user's Startup folder, with files marked hidden+system under Microsoft-lookalike names. Sensitive identifiers — 'childprocess', 'https', 'wscript.exe', 'APPDATA', the Microsoft/Windows/WinSxS/Backup path segments, 'winsvc.js', 'node.exe', the limbomail.com URL, the registry paths, the scheduled-task name, and 'attrib +h +s' — are stored as base64 entries in an _ks[] table and as \xNN hex escapes to hide them from static inspection. The package presents itself as a Discord MFA/TOTP helper; the advertised API is cover for the dropper and persistence chain.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019130",
"source": "amazon-inspector",
"import_time": "2026-08-29T02:22:20.020869192Z",
"modified_time": "2026-08-29T02:12:32Z",
"sha256": "6e8426c0e4e80e0bd9839d8517e060bd923775b8a3e100aab57e18b4f47c970e",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-019131",
"source": "amazon-inspector",
"import_time": "2026-08-29T02:22:20.166420316Z",
"modified_time": "2026-08-29T02:12:41Z",
"sha256": "dc8a8f485863642f8e0b605cb6fef6793b316153d5f55f5b38fbd7061844581d",
"versions": [
"1.0.3"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"package_integrity": [
{
"filename": "mfacord-1.0.2.tgz",
"hashes": {
"sha512_sri": "sha512-B1fxDQSlTnCOVzT0tWaDqgLOXGWX2jzUJY0dQ1h8hcOypHrDmM75CtnW7Cq6LbrIXsjmanej1R8rZxCtAvcU6Q==",
"sha1": "8b8e63f954337ec22598ad4b18534bdfeeea8f81"
}
}
],
"evidence_files": [
{
"path": "lib/cache.js",
"tlsh": "afb1d04a25f2a03751ab55ff5b4f81097227e4433148f986bf6cf2883fa2128c6a75d8",
"sha256": "ed894e38f515bd03e43a7eccec3917c5317124270d2fd22b536bf23696fc9a0b"
},
{
"path": "lib/totp.js",
"tlsh": "eb71fd9438f1e137229e85c3be279cb46167d0b17182f087ab6cb5ce1fda41bc6664d8",
"sha256": "8db6df3b347b9487cd74147360538a2cc10297ea891e5c7f1f0c3b99bede6678"
},
{
"path": "lib/crypto.js",
"tlsh": "ce3110057cd6b51c458a93f099afcc0a705ac822238a9a30725dda8e7fb5a38823684d",
"sha256": "2f167d3da6655f882f6ba1d8a4ec69728342100a02e35e7aa0fc1a133ec05105"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfacord/MAL-2026-15557.json"