LWA-2026-11754 MAL-2026-15629 ↗ confirmed malware

mfaatest@1.0.0

Malicious code in mfaatest (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1552.001 · Credentials In Files

Analysis

mfaatest@1.0.0 declares a runtime dependency "node-net-pool" fetched from a non-registry host (hxxps://limbomail[.]com/api/attachment/fpwvxc__9DvM[.]Bjuueu1K2SkBC_KkgATls-oq05UsrNNY/pkg[.]tgz) and loads it via require() when the package is imported, executing attacker-controlled code from that host. The package is also a Discord MFA/vanity-URL-sniping tool: it accepts a Discord user token and account password, requests MFA tickets from Discord's API (PATCH /api/v9/guilds/0/vanity-url, POST /api/v9/mfa/finish), and emits x-discord-mfa-authorization headers for PATCHing guild vanity URLs, i.e. it automates abuse of Discord accounts and their MFA credentials.

analyzed by
Leitwacht
first seen
Aug 29, 2026, 08:21 PM
analyzed
Aug 29, 2026, 08:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.