fastify-client-bundler@1.4.0
Malicious code in fastify-client-bundler (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat package impersonating a Fastify client bundler (the README describes a different package, "Tailwindcss Forms Bundler"). The exported getPlugin() function fetches a remote payload from a hardcoded IP address (31[.]97[.]137[.]157:45000) at path /icons/105 and executes it via new Function() with full Node.js context including require, process, and Buffer, enabling arbitrary remote code execution. The payload is served from the remote server at time of use, not shipped in the package itself. The C2 host is 31[.]97[.]137[.]157 on port 45000.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 08:40 PM
- analyzed
- Jul 22, 2026, 08:40 PM
Related advisories
- react-tabulix-ui@0.1.2
- encryptstringadmin@1.2.1
- poly-provider-api@4.6.1
- async-mutex-lock@5.3.1
- dbconnectify@1.0.2
- utility-kit-ts@1.3.2
- ts-toolkit-plus@1.3.2
- ventrix-kit@1.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.