Logo
npm

hridoy-ultimate@8.0.0

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 5:53 PM UTC

Malicious

OSV ID

MAL-2026-17803

Ecosystem

npm

Summary

hridoy-ultimate 8.0.0 is an unofficial Facebook chat client that contains two installer-harming behaviors. First, the password-based login path in module/loginHelper.js forwards caller-supplied Facebook email, password, and Base32 TOTP 2FA secret to a hardcoded third-party endpoint at https://minhdong.site/api/v1/facebook/login_ios (default baked into module/config.js, not disclosed in README) and receives the resulting Facebook session cookies / access_token back through that server, giving the operator of minhdong.site full access to any account whose credentials pass through this path. Second, package.json declares fca-unofficial as github:VangBanLaNhat/fca-unofficial with no commit SHA or tag; npm resolves this against whatever the referenced repository's default branch contains at install time, and the vendor bundle under src/api/socket/e2ee/ actually requires that module, so arbitrary code controlled by that GitHub repo owner is pulled and executed on the installer at install and load time with no integrity check and no version lock. A separate opt-in WebSocket remote-control client (src/remote/remoteClient.js) is config-gated and does not itself exec received data.

Source: amazon-inspector (221c8e51e1341e954c4f2ea3ea4a139606138c8ecc1ab99e17f403e304f05157)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.