OpenSSF/OSV advisory MAL-2026-17663 confirms this npm version as malicious. package.json at line 41 declares the only runtime dependency `node-net-pool` as `https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz` — an off-registry HTTP source pointing at the mutable `main` branch of a GitHub account unrelated to the mfasolver publisher, with no commit pin and no integrity hash...
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgThis report applies to mfasolver@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkg