LWA-2026-4258 confirmed malware

node-fastify@5.9.1

Malicious code in node-fastify (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1564.003 · Hidden Window

Analysis

node-fastify@5.9.1 is a combosquat of the real fastify framework, published by [account] The author claims to be Matteo Collina but the actual npm user is nenethrosas. The main entry point (fastify. The dependency 'child_process@^1.0.2' is listed to shadow Node's built-in child_process module. The code also misdeclares VERSION as '5.8.6' while published as 5.9.1, and the package ships no README. This is a supply-chain attack dropping second-stage malware on require().

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:57 AM
analyzed
Jun 11, 2026, 11:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.