MAL-2026-16440
Malicious code in turbo-ws (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a25d8c29cbfb317e1c88568514a999618bdeee25b2716b76e3db5062e9dd7a67) package.json at line 43 declares the sole dependency 'node-net-pool' as an HTTPS tarball of the 'main' branch of an unrelated GitHub account (https://github.com/trktgq0wbre1/node-net-pool/archive/refs/heads/main.tar.gz), not a registry version range. npm install fetches whatever bytes that URL currently serves, unpinned and with no integrity check, and runs any lifecycle scripts inside it; the package's postinstall then require()s node-net-pool so its top-level code executes on the installer's machine. The dependency source is under an account unrelated to the declared repository turbo-ws-dev/turbo-ws, and the package's own description advertises 'zero dependencies', contradicting the manifest. Whoever controls the referenced GitHub account controls code executed on every installer of turbo-ws.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for turbo-ws (npm). Pin to a known-safe version or switch to an alternative.