VYPR

npm · Malicious package advisory

Malware

ultimate-websocket

MAL-2026-17529

Malicious code in ultimate-websocket (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)
package.json declares its only dependency `node-net-pool` as a bare tarball URL pointing at the mutable `main` branch of an unrelated GitHub user (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so `npm install` fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own `scripts.postinstall` additionally executes `node -e "...require('node-net-pool')..."`, loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.