OpenSSF/OSV advisory MAL-2026-12379 confirms this npm version as malicious. index.js (the package main) defines a getPlugin() function that fetches JSON from a hardcoded bare-IP HTTPS endpoint at 31.97.137.157:45000 and compiles the response's `credits` field via `new Function(...)` with `require`, `module`, `exports`, `process`, `Buffer`, and `Promise` injected, then invokes it — granting the remote endpoint arbitrary code execution in the Node process that loads the package...
This report applies to fastify-client-bundler@1.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.