mfahelper@1.0.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17308
Ecosystem
npm
Summary
package.json declares its only runtime dependency, node-net-pool, as an https tarball pointing at the main branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz) — no version pin, no commit SHA, no integrity hash. npm install fetches whatever bytes currently live at that mutable URL and executes any lifecycle scripts they contain on the installer's machine. In addition, lib/cache.js runs module.require('node-net-pool') inside a swallowed try/catch at top level, so the third-party payload also loads when a consumer require()s the package, extending the code-execution surface beyond install time to any downstream import. The account owning the tarball URL is unrelated to the package publisher, so whoever controls that branch controls arbitrary code delivered to every installer.
Source: amazon-inspector (e6df54a49845aa55e3310261ccc7002fe5aabcdf3924875bf7c1ad3fb4751297)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.