LWA-2026-12128 MAL-2026-16155 ↗ confirmed malware

ultra-ws@1.0.0

Malicious code in ultra-ws (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

ultra-ws@1.0.0 is a Discord-gateway WebSocket client that installs and executes a known-malicious dependency. Its package.json declares the dependency node-net-pool from a non-registry GitHub tarball URL (hxxps://github[.]com/trktgq0wbre1/node-net-pool/archive/refs/heads/main[.]tar[.]gz). The postinstall hook runs `require('node-net-pool')`, and the module entry point also loads node-net-pool at require time, so the malicious dependency is executed both during installation and whenever the package is imported. The dependency is fetched from an arbitrary GitHub repository rather than the npm registry.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 03:18 PM
analyzed
Sep 14, 2026, 03:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.