OpenSSF/OSV advisory MAL-2026-16440 confirms this npm version as malicious. package.json at line 43 declares the sole dependency 'node-net-pool' as an HTTPS tarball of the 'main' branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), not a registry version range. npm install fetches whatever bytes that URL currently serves, unpinned and with no integrity check, and runs any lifecycle scripts inside it; the package's postinstall...
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgThis report applies to turbo-ws@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references weak cryptographic algorithms.
src/websocket.jsView on unpkg · L2Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
src/websocket.jsView on unpkg · L2