LWA-2026-11680 confirmed malware

mfa-js@1.0.4

Malicious code in mfa-js (npm)

T1059.007 · JavaScriptT1059.003 · Windows Command ShellT1547.001 · Registry Run Keys / Startup FolderT1547.004 · Winlogon Helper DLLT1053.005 · Scheduled TaskT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1027 · Obfuscated Files or InformationT1082 · System Information Discovery

Analysis

mfa-js is a Windows-targeting backdoor disguised as a Discord MFA/TOTP library. On Windows, the cache module decodes base64 constants to build the path %APPDATA%\Microsoft\Windows\WinSxS\Backup\winsvc.js, downloads a remote payload from hxxps://limbomail[.]com/api/attachment/r_Ea6rT_kGfT[.]o7nh0aBVvDQWmOG47NPBQ3pUjd_uHeiw (TLS verification disabled), and launches it detached via wscript.exe. The TOTP module installs persistence for the dropped script through four mechanisms: a registry Run key (WinSvcHost), the UserInitMprLogonScript registry value, a VBS file in the Startup folder, and a scheduled task (schtasks /sc onlogon). A two-hour update loop re-downloads and relaunches the payload. All strings are hex/base64-escaped to hide the behaviour.

analyzed by
Leitwacht
first seen
Aug 28, 2026, 04:03 PM
analyzed
Aug 28, 2026, 04:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.