-= Per source details. Do not edit below this line.=-
package.json declares its only runtime dependency, node-net-pool, as an https tarball pointing at the main branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz) — no version pin, no commit SHA, no integrity hash. npm install fetches whatever bytes currently live at that mutable URL and executes any lifecycle scripts they contain on the installer's machine. In addition, lib/cache.js runs module.require('node-net-pool') inside a swallowed try/catch at top level, so the third-party payload also loads when a consumer require()s the package, extending the code-execution surface beyond install time to any downstream import. The account owning the tarball URL is unrelated to the package publisher, so whoever controls that branch controls arbitrary code delivered to every installer.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020764",
"import_time": "2026-09-30T01:36:49.733150632Z",
"modified_time": "2026-09-30T01:00:23Z",
"sha256": "e6df54a49845aa55e3310261ccc7002fe5aabcdf3924875bf7c1ad3fb4751297",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "dcc2b8f9ad403eb63837113d9f5999f655c756105f53e032ccb8fb1a0d70161d",
"tlsh": "03216e26c9e81c5317e52590a8154162b5720c070b59bc1473ca826e8fdd17f22ff95e"
},
{
"path": "lib/cache.js",
"sha256": "40ad444731103c356ac7643b1a58e6093fcce1ea2f43977fb07f34833d37178a",
"tlsh": "1f416c5f39c1f0261bf7a57da91f874ab76c990c200cd5a0796943ecba3213c47b7859"
},
{
"path": "index.js",
"sha256": "0e3494d24c490978c9e5e3d8b13e45fd261b6fac692f852045ff8b4241b3b63f",
"tlsh": "7a12621121f7203a0367d0ff9bd7d01567345903355ae9b8b78c9684afc361a85b3aee"
}
],
"package_integrity": [
{
"filename": "mfahelper-1.0.0.tgz",
"hashes": {
"sha1": "84aeb8f516010c62bea1961841beb3096fe45355",
"sha512_sri": "sha512-Jia7ZhtXeWTU6dMGynpNLjQVmUdEdJOeAib+vASBGmyR0eVb4hJg0MzAE3UMFilG2QRFh/oiOUPvRysvCoMTkQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfahelper/MAL-2026-17308.json"