OpenSSF/OSV advisory MAL-2026-16102 confirms this npm version as malicious. package.json declares its only runtime dependency as an unpinned GitHub ref (`"node-net-pool": "github:trktgq0wbre1/node-net-pool"`) pointing at a random-handle user account, contradicting the package's own 'Zero runtime dependencies — pure Node.js built-ins only' claim in the README. npm install resolves whatever HEAD of that repository currently returns, and lib/cache.js executes a top-level require of that...
This report applies to mfatest2@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.