OpenSSF/OSV advisory MAL-2026-17308 confirms this npm version as malicious. package.json declares its only runtime dependency, `node-net-pool`, as an https tarball pointing at the `main` branch of an unrelated GitHub account (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`) — no version pin, no commit SHA, no integrity hash...
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgThis report applies to mfahelper@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkg