npm · Malicious package advisory
Malwareultimate-websocket
MAL-2026-17529
Malicious code in ultimate-websocket (npm)
Details
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)
package.json declares its only dependency `node-net-pool` as a bare tarball URL pointing at the mutable `main` branch of an unrelated GitHub user (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so `npm install` fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own `scripts.postinstall` additionally executes `node -e "...require('node-net-pool')..."`, loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.