LWA-2026-6576 MAL-2026-10098 ↗ confirmed malware

fastify-addone@5.1.0

Malicious code in fastify-addone (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

fastify-addone@5.1.0 is a typosquat of the legitimate fastify-plugin package. On require(), the file lib/getPluginName.js executes a top-level fetch to hxxps://www[.]jsonkeeper[.]com/b/HDXPP, retrieves JSON content, and passes it to eval() — achieving remote code execution on every import. The fetched payload is served from www[.]jsonkeeper[.]com and is fully attacker-controlled, enabling arbitrary code execution in the context of any project that depends on this package.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:23 PM
analyzed
Jul 9, 2026, 11:24 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.