Importing the package loads an unpinned remote dependency. Calling initMFA transmits supplied Discord credentials with certificate validation disabled and produces reusable MFA authorization tokens.
The package installs node-net-pool from an unpinned GitHub branch tarball.
package.jsonView on unpkg · L41Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgImporting the cache module immediately attempts to load that remote dependency while suppressing any failure.
lib/cache.jsView on unpkg · L2The MFA flow disables TLS certificate validation, then sends the supplied Discord token and password to Discord API paths.
index.jsView on unpkg · L26The MFA flow disables TLS certificate validation, then sends the supplied Discord token and password to Discord API paths.
index.jsView on unpkg · L156This report applies to discord-mfa-solver@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The package installs node-net-pool from an unpinned GitHub branch tarball.
package.jsonView on unpkg · L41Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgImporting the cache module immediately attempts to load that remote dependency while suppressing any failure.
lib/cache.jsView on unpkg · L2The MFA flow disables TLS certificate validation, then sends the supplied Discord token and password to Discord API paths.
index.jsView on unpkg · L26The MFA flow disables TLS certificate validation, then sends the supplied Discord token and password to Discord API paths.
index.jsView on unpkg · L156