npm

node-net-pool @1.0.0

Vulnerability report · Last retrieved from osv.dev August 31, 2026 at 7:41 PM UTC

Malicious

OSV ID

MAL-2026-15570

Ecosystem

npm

Summary

package.json declares a postinstall hook ( node index.js ) that runs automatically on npm install . The shipped index.js contains no networking or connection-pool code — the entire file body is a ~6.3KB numeric byte array ( _s ) decoded by a custom LCG+XOR routine ( _d(a,k) using state p*0x41C64E6D+0x3039 & 0xFFFF XORed byte-wise) and passed directly to new Function(_d(_s,179))() , dynamically evaluating the decoded payload on the installer's machine at install time. The manifest advertises the package as 'Node.js network connection pool utilities' with main: index.js , but index.js exports nothing and only runs the obfuscated executor — the stated purpose does not match the shipped contents. Install-time evaluation of an opaque, obfuscated payload with no legitimate build-step justification, combined with the cover-story metadata, is a supply-chain dropper/RCE pattern.

Source: amazon-inspector (d9c6bb87249429b2a3f3791589075bf872a433bd47a33b152f6809ccf94b1328)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.