LWA-2026-11728 confirmed malware

mfafix@1.0.0

Malicious code in mfafix (npm)

T1105 · Ingress Tool TransferT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

mfafix is a Discord MFA/vanity-URL tool that also contains a remote code execution backdoor. Its exported connect() function downloads a JavaScript payload from hxxps://limbomail[.]com/api/attachment/l4TIRPOsaUxR[.]_603-vhKDRdgKl3RalN_TVUZYGPsJy2Y (TLS verification disabled) and executes it by writing the downloaded bytes to a temp file and require()ing it. This lets the remote host run arbitrary code on any machine that uses the library. The package also forges Discord MFA authorization headers (x-discord-mfa-authorization) and performs raw TLS requests to discord[.]com to obtain MFA tokens for vanity-URL sniping.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 01:14 PM
analyzed
Aug 29, 2026, 01:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.