hridoy-ultimate@8.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 5:53 PM UTC
OSV ID
MAL-2026-17803
Ecosystem
npm
Summary
hridoy-ultimate 8.0.0 is an unofficial Facebook chat client that contains two installer-harming behaviors. First, the password-based login path in module/loginHelper.js forwards caller-supplied Facebook email, password, and Base32 TOTP 2FA secret to a hardcoded third-party endpoint at https://minhdong.site/api/v1/facebook/login_ios (default baked into module/config.js, not disclosed in README) and receives the resulting Facebook session cookies / access_token back through that server, giving the operator of minhdong.site full access to any account whose credentials pass through this path. Second, package.json declares fca-unofficial as github:VangBanLaNhat/fca-unofficial with no commit SHA or tag; npm resolves this against whatever the referenced repository's default branch contains at install time, and the vendor bundle under src/api/socket/e2ee/ actually requires that module, so arbitrary code controlled by that GitHub repo owner is pulled and executed on the installer at install and load time with no integrity check and no version lock. A separate opt-in WebSocket remote-control client (src/remote/remoteClient.js) is config-gated and does not itself exec received data.
Source: amazon-inspector (221c8e51e1341e954c4f2ea3ea4a139606138c8ecc1ab99e17f403e304f05157)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.