ultimate-websocket@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17529
Ecosystem
npm
Summary
package.json declares its only dependency node-net-pool as a bare tarball URL pointing at the mutable main branch of an unrelated GitHub user (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so npm install fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own scripts.postinstall additionally executes node -e "...require('node-net-pool')...", loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.
Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.