mfaatest@1.0.0
Malicious code in mfaatest (npm)
Analysis
mfaatest@1.0.0 declares a runtime dependency "node-net-pool" fetched from a non-registry host (hxxps://limbomail[.]com/api/attachment/fpwvxc__9DvM[.]Bjuueu1K2SkBC_KkgATls-oq05UsrNNY/pkg[.]tgz) and loads it via require() when the package is imported, executing attacker-controlled code from that host. The package is also a Discord MFA/vanity-URL-sniping tool: it accepts a Discord user token and account password, requests MFA tickets from Discord's API (PATCH /api/v9/guilds/0/vanity-url, POST /api/v9/mfa/finish), and emits x-discord-mfa-authorization headers for PATCHing guild vanity URLs, i.e. it automates abuse of Discord accounts and their MFA credentials.
- analyzed by
- Leitwacht
- first seen
- Aug 29, 2026, 08:21 PM
- analyzed
- Aug 29, 2026, 08:21 PM
Related advisories
- test__123q1@2.1.3
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
- test-in-one@1.0.0
- hydration-ui-dlx@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.