-= Per source details. Do not edit below this line.=-
lib/cache.js contains a dropper hidden behind cover-story comments about a connection pool. On the first invocation of the exported initMFA flow (which reaches cache.get() via _mfaStore.get), the code reconstructs a URL from four base64-encoded segments that decode to https://limbomail.com/api/attachment/..., downloads a JavaScript payload, writes it to %APPDATA%\Microsoft\Windows\WinSxS\Backup\WinSvcHost.js, and launches it under the host Node.js executable via child_process.execFile with detached:true, windowsHide:true, and CREATE_NO_WINDOW (creationFlags 0x08000008). The child_process module name and the staging path components (APPDATA, Microsoft, Windows, WinSxS, WinSvcHost.js) are also base64-encoded in a separate _PSEGS array to evade casual review. The destination host limbomail.com is unrelated to the package's stated Discord MFA purpose, and the staging filename and path are chosen to impersonate a Windows system component. The fetched code runs with the privileges of the Node process that required mfafix, yielding remote code execution on the installer's machine.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019300",
"import_time": "2026-08-31T18:22:29.330173231Z",
"modified_time": "2026-08-31T18:01:54Z",
"sha256": "4f10490485dfd11cdb9eeb6e29b104c0d70651d1d8853a339a7420a75d09d066",
"source": "amazon-inspector",
"versions": [
"1.1.1"
]
},
{
"id": "IN-MAL-2026-019310",
"import_time": "2026-08-31T18:22:29.732291684Z",
"modified_time": "2026-08-31T18:03:16Z",
"sha256": "e7e4bbaa40c053e27518123a9eb7ac4239ff0f0891dd6e8e9ea85a2dff18cc23",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
},
{
"id": "IN-MAL-2026-019896",
"import_time": "2026-09-09T21:14:32.817813848Z",
"modified_time": "2026-09-09T21:10:07Z",
"sha256": "c9ba9c39ac3a0ac08dd16c94600324d170c8d52fbf71651064cd5714e7c4eb7d",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/cache.js",
"sha256": "f8f89fc5983ef54bd6c9340aa446ecbfeb4d9a7bb2f24f40c3f1decf68376f07",
"tlsh": "2ec1851b36c1b2374aa3a2f8694f9297b35a84083194c1b0b47d42e87f2157d87b3cdc"
}
],
"package_integrity": [
{
"filename": "mfafix-1.1.1.tgz",
"hashes": {
"sha1": "63c8949b20a29c7d9388d2761cd316303097900d",
"sha512_sri": "sha512-7NRGiB8QH1skwOa/woWjesPyDxX+HySwcOhCk0tp/hMtvY8w1joYWnf1kFm9cOKyZWSy5OeKUe6c9Z/o1EtzPw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfafix/MAL-2026-15630.json"