OpenSSF/OSV advisory MAL-2026-17529 confirms this npm version as malicious. package.json declares its only dependency `node-net-pool` as a bare tarball URL pointing at the mutable `main` branch of an unrelated GitHub user (`https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz`), bypassing the npm registry entirely...
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
src/websocket.jsView on unpkg · L2This report applies to ultimate-websocket@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
src/websocket.jsView on unpkg · L2