MAL-2026-17529

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ultimate-websocket/MAL-2026-17529.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17529
Published
2026-10-04T23:24:41Z
Modified
2026-10-04T23:45:23Z
Summary
Malicious code in ultimate-websocket (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114)

package.json declares its only dependency node-net-pool as a bare tarball URL pointing at the mutable main branch of an unrelated GitHub user (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so npm install fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own scripts.postinstall additionally executes node -e "...require('node-net-pool')...", loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020949",
            "import_time":  "2026-10-04T23:40:45.062055495Z",
            "modified_time":  "2026-10-04T23:24:41Z",
            "sha256":  "7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / ultimate-websocket

Package

Name
ultimate-websocket
View open source insights on deps.dev
Purl
pkg:npm/ultimate-websocket

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "269550b89954bd89b6ac0a5f97de299d514efc96737b03ce923adac33fd8c089",
            "tlsh":  "e2411066cdb9d6eb38e502f4f41a5156fa2248030a54bc5cb3c249ac8bcf4ab80fe55d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "ultimate-websocket-1.0.0.tgz",
            "hashes":  {
                "sha1":  "1d891216d9b120c986fddde1607ff149c87bd2ca",
                "sha512_sri":  "sha512-ALRhOhHdKYuvVE9Nyw21ppR2thXF0yixlEcpfH/wKdCO3vrIaaafO6WTXst8GcRopgl1x/Sjef2+GuXFOg+XFg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ultimate-websocket/MAL-2026-17529.json"