MAL-2026-12379
Malicious code in fastify-client-bundler (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (370379b65a0c7e31b5bf43362a0c1fa1312f9a458a7af9a4a3d95892dc2a6935) index.js (the package main) defines a getPlugin() function that fetches JSON from a hardcoded bare-IP HTTPS endpoint at 31.97.137.157:45000 and compiles the response's `credits` field via `new Function(...)` with `require`, `module`, `exports`, `process`, `Buffer`, and `Promise` injected, then invokes it — granting the remote endpoint arbitrary code execution in the Node process that loads the package. The package's declared purpose (a Fastify client bundler / Tailwindcss forms bundler) and CDN-style helpers (setDefaultModule constructing cdnjs URLs) are unused decoys; the actually-invoked network path targets the bare IP. Bundled runtime dependencies (@primno/dpapi, better-sqlite3, node-machine-id) are consistent with a Windows credential/wallet stealer that a delivered payload would load through the injected `require`.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for fastify-client-bundler (npm). Pin to a known-safe version or switch to an alternative.