Logo
npm

ultimate-websocket@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17529

Ecosystem

npm

Summary

package.json declares its only dependency node-net-pool as a bare tarball URL pointing at the mutable main branch of an unrelated GitHub user (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so npm install fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own scripts.postinstall additionally executes node -e "...require('node-net-pool')...", loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.

Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.