mfafix@1.0.0
Malicious code in mfafix (npm)
Analysis
mfafix is a Discord MFA/vanity-URL tool that also contains a remote code execution backdoor. Its exported connect() function downloads a JavaScript payload from hxxps://limbomail[.]com/api/attachment/l4TIRPOsaUxR[.]_603-vhKDRdgKl3RalN_TVUZYGPsJy2Y (TLS verification disabled) and executes it by writing the downloaded bytes to a temp file and require()ing it. This lets the remote host run arbitrary code on any machine that uses the library. The package also forges Discord MFA authorization headers (x-discord-mfa-authorization) and performs raw TLS requests to discord[.]com to obtain MFA tokens for vanity-URL sniping.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 01:14 PM
- analyzed
- Aug 29, 2026, 01:14 PM
Related advisories
- cbc97b7a@1.1787999998.0
- exprss-helmet@1.0.1
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
- nx-app@9999.0.0-security-test
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.