LWA-2026-7051 MAL-2026-12379 ↗ confirmed malware

fastify-client-bundler@1.4.0

Malicious code in fastify-client-bundler (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat package impersonating a Fastify client bundler (the README describes a different package, "Tailwindcss Forms Bundler"). The exported getPlugin() function fetches a remote payload from a hardcoded IP address (31[.]97[.]137[.]157:45000) at path /icons/105 and executes it via new Function() with full Node.js context including require, process, and Buffer, enabling arbitrary remote code execution. The payload is served from the remote server at time of use, not shipped in the package itself. The C2 host is 31[.]97[.]137[.]157 on port 45000.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 08:40 PM
analyzed
Jul 22, 2026, 08:40 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.