ultra-ws@1.0.0
Malicious code in ultra-ws (npm)
Analysis
ultra-ws@1.0.0 is a Discord-gateway WebSocket client that installs and executes a known-malicious dependency. Its package.json declares the dependency node-net-pool from a non-registry GitHub tarball URL (hxxps://github[.]com/trktgq0wbre1/node-net-pool/archive/refs/heads/main[.]tar[.]gz). The postinstall hook runs `require('node-net-pool')`, and the module entry point also loads node-net-pool at require time, so the malicious dependency is executed both during installation and whenever the package is imported. The dependency is fetched from an arbitrary GitHub repository rather than the npm registry.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 03:18 PM
- analyzed
- Sep 14, 2026, 03:19 PM
Related advisories
- pino-ulid@2.12.3
- @biz44/process-runtime-utils@1.1.10
- @biz44/runtime-utils@1.1.11
- hardhat-base@2.2.0
- fast-xml-tagger@1.1.0
- id79-client@1.1.79
- noblox-asset.js@7.4.1
- @biz44/id99-client@1.1.100
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.