MAL-2026-17663

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfasolver/MAL-2026-17663.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17663
Published
2026-10-08T03:45:15Z
Modified
2026-10-08T04:00:04Z
Summary
Malicious code in mfasolver (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6f583d18816b977d3e721da8423405533e9915ad13631d8114e40e54aefd9152)

package.json at line 41 declares the only runtime dependency node-net-pool as https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz — an off-registry HTTP source pointing at the mutable main branch of a GitHub account unrelated to the mfasolver publisher, with no commit pin and no integrity hash. npm install mfasolver fetches whatever bytes that URL returns at install time and runs any lifecycle scripts contained in the fetched archive. The dependency is additionally force-loaded on require: lib/cache.js top-level calls module['require']('node-net-pool') inside a try/catch, so importing mfasolver also executes the attacker-controllable code. Separately, index.js opens TLS connections to discord.com with rejectUnauthorized: false, disabling certificate validation on the package's own Discord traffic.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021135",
            "import_time": "2026-10-08T03:50:30.198048342Z",
            "modified_time": "2026-10-08T03:45:15Z",
            "sha256": "6f583d18816b977d3e721da8423405533e9915ad13631d8114e40e54aefd9152",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / mfasolver

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "9a2e278313d5b3de621650624f5f3cced6c9eccccc0a817e15d69294eb4d4534",
            "tlsh": "1c217c26c8e82c5717c569e0ec198152b6721c070949bc1473ca86ad8f9e0bb22bf19e"
        },
        {
            "path": "index.js",
            "sha256": "0e3494d24c490978c9e5e3d8b13e45fd261b6fac692f852045ff8b4241b3b63f",
            "tlsh": "7a12621121f7203a0367d0ff9bd7d01567345903355ae9b8b78c9684afc361a85b3aee"
        }
    ],
    "package_integrity": [
        {
            "filename": "mfasolver-1.0.0.tgz",
            "hashes": {
                "sha1": "483447cc8b62e8513429f41918dc7c34221e4034",
                "sha512_sri": "sha512-w5ICuAK1UhxTAhMBnfr8QEDWo6wWpSx7rfdRdPFhgjXfFdxLw0UPirEiBczbQ/KpBkRVYkqmpWEPp9Fn1kBuuA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mfasolver/MAL-2026-17663.json"