MAL-2026-15629

    Dashboard / Malicious Package / MAL-2026-15629

    MAL-2026-15629

    Published: 31 Aug 2026Last Modified: 31 Aug 2026

    Summary: Malicious code in mfaatest (npm)

    Details: Source: amazon-inspector (73e4ce261829117e316f9152160cdcb35c6ba66064f631baba1f8d528673b584) package.json declares dependency `node-net-pool` with its value set to an arbitrary HTTPS tarball URL (`https://limbomail.com/api/attachment/fpwvxc__9DvM.Bjuueu1K2SkBC_KkgATls-oq05UsrNNY/pkg.tgz`) rather than a registry version range. On `npm install`, npm fetches whatever bytes limbomail.com returns and installs them, executing any lifecycle scripts inside the fetched tarball. The source is unpinned, integrity-unchecked, and hosted on a domain unrelated to the package's stated publisher; the content can be swapped at any time by whoever controls that host. The package's own description claims 'zero runtime dependencies', contradicting the presence of this off-registry dependency and matching the smuggled-dropper shape.

    Affected packages

    Package

    Name: mfaatest

    Purl: pkg:npm/mfaatest

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0