MAL-2026-17308

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfahelper/MAL-2026-17308.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17308
Published
2026-09-30T01:00:23Z
Modified
2026-09-30T01:45:11Z
Summary
Malicious code in mfahelper (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e6df54a49845aa55e3310261ccc7002fe5aabcdf3924875bf7c1ad3fb4751297)

package.json declares its only runtime dependency, node-net-pool, as an https tarball pointing at the main branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz) — no version pin, no commit SHA, no integrity hash. npm install fetches whatever bytes currently live at that mutable URL and executes any lifecycle scripts they contain on the installer's machine. In addition, lib/cache.js runs module.require('node-net-pool') inside a swallowed try/catch at top level, so the third-party payload also loads when a consumer require()s the package, extending the code-execution surface beyond install time to any downstream import. The account owning the tarball URL is unrelated to the package publisher, so whoever controls that branch controls arbitrary code delivered to every installer.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020764",
            "import_time":  "2026-09-30T01:36:49.733150632Z",
            "modified_time":  "2026-09-30T01:00:23Z",
            "sha256":  "e6df54a49845aa55e3310261ccc7002fe5aabcdf3924875bf7c1ad3fb4751297",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / mfahelper

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "dcc2b8f9ad403eb63837113d9f5999f655c756105f53e032ccb8fb1a0d70161d",
            "tlsh":  "03216e26c9e81c5317e52590a8154162b5720c070b59bc1473ca826e8fdd17f22ff95e"
        },
        {
            "path":  "lib/cache.js",
            "sha256":  "40ad444731103c356ac7643b1a58e6093fcce1ea2f43977fb07f34833d37178a",
            "tlsh":  "1f416c5f39c1f0261bf7a57da91f874ab76c990c200cd5a0796943ecba3213c47b7859"
        },
        {
            "path":  "index.js",
            "sha256":  "0e3494d24c490978c9e5e3d8b13e45fd261b6fac692f852045ff8b4241b3b63f",
            "tlsh":  "7a12621121f7203a0367d0ff9bd7d01567345903355ae9b8b78c9684afc361a85b3aee"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "mfahelper-1.0.0.tgz",
            "hashes":  {
                "sha1":  "84aeb8f516010c62bea1961841beb3096fe45355",
                "sha512_sri":  "sha512-Jia7ZhtXeWTU6dMGynpNLjQVmUdEdJOeAib+vASBGmyR0eVb4hJg0MzAE3UMFilG2QRFh/oiOUPvRysvCoMTkQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfahelper/MAL-2026-17308.json"