LWA-2026-4258 confirmed malware
node-fastify@5.9.1
Malicious code in node-fastify (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1564.003 · Hidden Window
Analysis
node-fastify@5.9.1 is a combosquat of the real fastify framework, published by [account] The author claims to be Matteo Collina but the actual npm user is nenethrosas. The main entry point (fastify. The dependency 'child_process@^1.0.2' is listed to shadow Node's built-in child_process module. The code also misdeclares VERSION as '5.8.6' while published as 5.9.1, and the package ships no README. This is a supply-chain attack dropping second-stage malware on require().
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:57 AM
- analyzed
- Jun 11, 2026, 11:59 AM
Related advisories
- node-fastify@5.8.7 same package
- node-fastify@5.8.8 same package
- node-fastify@5.8.9 same package
- node-fastify@5.9.0 same package
- node-fetch-lite@1.0.2
- node-env-resolve@1.0.0
- nodecheck-health@1.0.0
- ts-eslint-helper@4.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.