{"id":"MAL-2026-12379","summary":"Malicious code in fastify-client-bundler (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (370379b65a0c7e31b5bf43362a0c1fa1312f9a458a7af9a4a3d95892dc2a6935)\nindex.js (the package main) defines a getPlugin() function that fetches JSON from a hardcoded bare-IP HTTPS endpoint at 31.97.137.157:45000 and compiles the response's `credits` field via `new Function(...)` with `require`, `module`, `exports`, `process`, `Buffer`, and `Promise` injected, then invokes it — granting the remote endpoint arbitrary code execution in the Node process that loads the package. The package's declared purpose (a Fastify client bundler / Tailwindcss forms bundler) and CDN-style helpers (setDefaultModule constructing cdnjs URLs) are unused decoys; the actually-invoked network path targets the bare IP. Bundled runtime dependencies (@primno/dpapi, better-sqlite3, node-machine-id) are consistent with a Windows credential/wallet stealer that a delivered payload would load through the injected `require`.\n","modified":"2026-08-05T13:35:25.854821129Z","published":"2026-08-05T13:01:48Z","database_specific":{"malicious-packages-origins":[{"sha256":"370379b65a0c7e31b5bf43362a0c1fa1312f9a458a7af9a4a3d95892dc2a6935","source":"amazon-inspector","versions":["1.4.0"],"id":"IN-MAL-2026-014854","import_time":"2026-08-05T13:08:51.231773893Z","modified_time":"2026-08-05T13:01:48Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fastify-client-bundler/v/1.4.0"}],"affected":[{"package":{"name":"fastify-client-bundler","ecosystem":"npm","purl":"pkg:npm/fastify-client-bundler"},"versions":["1.4.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"96c1726546fa31a36a67e4edf30f100271a5e313375ce971f48e42902fca568e5f24e8","path":"index.js","sha256":"e46d14bcb6b21b782972b143ba8b7f1e3dda376047a12426e776f5ae2106a2d8"},{"sha256":"f50c206cee430e388e406cf96ae68ec6a32727bec8712e338021d3119c4e36f5","tlsh":"3b014910ce218eb715d92652982d9186e261dc4b8e11fc0c33da479c9f4e57f27fe66c","path":"package.json"}],"package_integrity":[{"filename":"fastify-client-bundler-1.4.0.tgz","hashes":{"sha1":"9567bad6193e59e2a79118569924da56fedc16f4","sha512_sri":"sha512-d20kiu5os1j9hQhXHaB4kTB7oRnhIFE3WwBIamogZUlhYHQTgSBtUYSIcGDEyKTPdp8jih6LCZJXOTbnbLce4w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fastify-client-bundler/MAL-2026-12379.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}