Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16101 confirms this npm version as malicious. The package presents itself as a Discord MFA helper, but its cache module contains a _warmSession routine that decodes a base64-encoded string (_CDN_BASE) into the URL https://limbomail.com/api/attachment/l4TIRPOsaUxR._603-vhKDRdgKl3RalN_TVUZYGPsJy2Y, downloads the response body, writes it to a file in os.tmpdir(), and executes it via new Worker(tmp)...
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/http.jsView on unpkg · L1This report applies to mfaby@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/http.jsView on unpkg · L1