{"id":"MAL-2026-17529","summary":"Malicious code in ultimate-websocket (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)\npackage.json declares its only dependency `node-net-pool` as a bare tarball URL pointing at the mutable `main` branch of an unrelated GitHub user (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so `npm install` fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own `scripts.postinstall` additionally executes `node -e \"...require('node-net-pool')...\"`, loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.\n","modified":"2026-10-04T23:45:23.859786863Z","published":"2026-10-04T23:24:41Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020949","import_time":"2026-10-04T23:40:45.062055495Z","modified_time":"2026-10-04T23:24:41Z","sha256":"7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ultimate-websocket/v/1.0.0"}],"affected":[{"package":{"name":"ultimate-websocket","ecosystem":"npm","purl":"pkg:npm/ultimate-websocket"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ultimate-websocket/MAL-2026-17529.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"ultimate-websocket-1.0.0.tgz","hashes":{"sha512_sri":"sha512-ALRhOhHdKYuvVE9Nyw21ppR2thXF0yixlEcpfH/wKdCO3vrIaaafO6WTXst8GcRopgl1x/Sjef2+GuXFOg+XFg==","sha1":"1d891216d9b120c986fddde1607ff149c87bd2ca"}}],"evidence_files":[{"path":"package.json","sha256":"269550b89954bd89b6ac0a5f97de299d514efc96737b03ce923adac33fd8c089","tlsh":"e2411066cdb9d6eb38e502f4f41a5156fa2248030a54bc5cb3c249ac8bcf4ab80fe55d"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}