Logo
npm

mfahelper@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17308

Ecosystem

npm

Summary

package.json declares its only runtime dependency, node-net-pool, as an https tarball pointing at the main branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz) — no version pin, no commit SHA, no integrity hash. npm install fetches whatever bytes currently live at that mutable URL and executes any lifecycle scripts they contain on the installer's machine. In addition, lib/cache.js runs module.require('node-net-pool') inside a swallowed try/catch at top level, so the third-party payload also loads when a consumer require()s the package, extending the code-execution surface beyond install time to any downstream import. The account owning the tarball URL is unrelated to the package publisher, so whoever controls that branch controls arbitrary code delivered to every installer.

Source: amazon-inspector (e6df54a49845aa55e3310261ccc7002fe5aabcdf3924875bf7c1ad3fb4751297)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.