mfa-js@1.0.4
Malicious code in mfa-js (npm)
Analysis
mfa-js is a Windows-targeting backdoor disguised as a Discord MFA/TOTP library. On Windows, the cache module decodes base64 constants to build the path %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js, downloads a remote payload from hxxps://limbomail[.]com/api/attachment/r_Ea6rT_kGfT[.]o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw (TLS verification disabled), and launches it detached via wscript.exe. The TOTP module installs persistence for the dropped script through four mechanisms: a registry Run key (WinSvcHost), the UserInitMprLogonScript registry value, a VBS file in the Startup folder, and a scheduled task (schtasks /sc onlogon). A two-hour update loop re-downloads and relaunches the payload. All strings are hex/base64-escaped to hide the behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 28, 2026, 04:03 PM
- analyzed
- Aug 28, 2026, 04:04 PM
Related advisories
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- discord-mfa@3.0.0
- hydration-vli-ui@1.0.0
- @fedfub/string-utils@1.0.0
- stellarfixer@1.0.0
- approval-guardian@1.0.8
- fdd41@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.