{"id":"MAL-2026-16440","summary":"Malicious code in turbo-ws (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a25d8c29cbfb317e1c88568514a999618bdeee25b2716b76e3db5062e9dd7a67)\npackage.json at line 43 declares the sole dependency 'node-net-pool' as an HTTPS tarball of the 'main' branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), not a registry version range. npm install fetches whatever bytes that URL currently serves, unpinned and with no integrity check, and runs any lifecycle scripts inside it; the package's postinstall then require()s node-net-pool so its top-level code executes on the installer's machine. The dependency source is under an account unrelated to the declared repository turbo-ws-dev/turbo-ws, and the package's own description advertises 'zero dependencies', contradicting the manifest. Whoever controls the referenced GitHub account controls code executed on every installer of turbo-ws.\n","modified":"2026-09-23T02:30:05.483156602Z","published":"2026-09-23T01:58:25Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-23T01:58:25Z","sha256":"a25d8c29cbfb317e1c88568514a999618bdeee25b2716b76e3db5062e9dd7a67","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020333","import_time":"2026-09-23T02:26:00.41189189Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/turbo-ws/v/1.0.0"}],"affected":[{"package":{"name":"turbo-ws","ecosystem":"npm","purl":"pkg:npm/turbo-ws"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"package.json","sha256":"7f84ab7675f41e8f3c5dcaac3b100d6c4b427050928faa07470c2880047ad50d","tlsh":"2031ea2ac9b899bb35c511e4e8195113f66208234998bd00b3c341fc4fce5db91ff5ad"}],"package_integrity":[{"hashes":{"sha1":"f00fff966b59f22fa0ff25b60b1243e1dc8a5bc8","sha512_sri":"sha512-KQ+nijvvuiPSjc9683PuqAC1/FMUgUFvuf7EIi+0al8GW6mpd5wcpC1Z7kUiab0VsXtSqMmMOTxrWTEwVVBu8g=="},"filename":"turbo-ws-1.0.0.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/turbo-ws/MAL-2026-16440.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}