SafeDep
Install GitHub App

Summary

The package is not a malware. YARA matches in test and documentation files are likely false positives. The project is popular and legitimate.

Verification Record

No verification record available.

Details

The package is not a malware. The YARA rule obfuscated_payload matched multiple test files (constrained-routes.test.js, hooks.test.js, and stream.1.test.js). Test files often contain payloads for testing purposes, so these matches are likely false positives. The YARA rule content_length_hardcoded matched a documentation file (Delay-Accepting-Requests.md). Hardcoded content lengths in documentation examples are not necessarily malicious. The project has a high number of stars and forks, indicating it is a popular and likely legitimate project.

fastify@5.8.3Clean
Unverified
Analysed at: 3/23/26, 10:27 AM
Source: https://registry.npmjs.org/fastify/-/fastify-5.8.3.tgz
SHA256: cd595b5923b945837748272573c40b2832b306461a603809465f44c2a4f750fa
Confidence: Medium