-= Per source details. Do not edit below this line.=-
package.json declares its only dependency node-net-pool as a bare tarball URL pointing at the mutable main branch of an unrelated GitHub user (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), bypassing the npm registry entirely. There is no version pin, no commit SHA, and no integrity hash, so npm install fetches whatever bytes that URL currently returns and runs any lifecycle scripts contained in them. The package's own scripts.postinstall additionally executes node -e "...require('node-net-pool')...", loading the fetched module at install time so its top-level code also runs on the installer's host. The GitHub account is a throwaway-shaped handle unrelated to the publishing identity, and the shipped tarball contains no real functionality — its only install-time effect is to pull and execute attacker-controlled code from an endpoint whose contents the author can change at any time.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020949",
"import_time": "2026-10-04T23:40:45.062055495Z",
"modified_time": "2026-10-04T23:24:41Z",
"sha256": "7574e423b830695141ee6e089006e0c355109e240c69881512806869cfee8114",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "269550b89954bd89b6ac0a5f97de299d514efc96737b03ce923adac33fd8c089",
"tlsh": "e2411066cdb9d6eb38e502f4f41a5156fa2248030a54bc5cb3c249ac8bcf4ab80fe55d"
}
],
"package_integrity": [
{
"filename": "ultimate-websocket-1.0.0.tgz",
"hashes": {
"sha1": "1d891216d9b120c986fddde1607ff149c87bd2ca",
"sha512_sri": "sha512-ALRhOhHdKYuvVE9Nyw21ppR2thXF0yixlEcpfH/wKdCO3vrIaaafO6WTXst8GcRopgl1x/Sjef2+GuXFOg+XFg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ultimate-websocket/MAL-2026-17529.json"