VYPR

npm · Malicious package advisory

Malware

ultimate-websocket

GHSA-w8c4-4fjc-rg48

Malicious code in ultimate-websocket (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)
package.json declares its only dependency `node-net-pool` as a bare tarball URL pointing at the mutable `main` branch of an unrelated GitHub user (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so `npm install` fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own `scripts.postinstall` additionally executes `node -e "...require('node-net-pool')..."`, loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/ultimate-websocket/MAL-2026-17529.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/ultimate-websocket/MAL-2026-17529.json
- https://www.npmjs.com/package/ultimate-websocket/v/1.0.0
- https://github.com/advisories/GHSA-w8c4-4fjc-rg48

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.