MAL-2026-11203

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dexwilt/node-fetch/MAL-2026-11203.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11203
Published
2026-06-22T10:44:41Z
Modified
2026-08-04T22:04:50Z
Summary
Malicious code in @dexwilt/node-fetch (npm)
Details

The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.

Agent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (416d6cd82361af6b046d895f23d5e82a82db236a104726914595c21288e33ed0)

@dexwilt/node-fetch impersonates the popular node-fetch package under a personal scope. Its main entrypoint (lib/index.js, lib/index.mjs, lib/index.es.js) ships the legitimate node-fetch v2 source with two appended, heavily obfuscated self-executing IIFEs that contain RC4+base64 string-array decoders reconstructing calls to https.request, fs.writeFileSync, fs.chmodSync, and child_process.spawn. Execution is gated on process.env.npm_config_user_agent — set by npm/yarn/pnpm during install but absent in plain node/REPL runs — so the payload only fires inside real installs while staying dormant during casual inspection. When triggered, the code re-spawns the current Node process detached with stdio ignored, downloads a remote binary over HTTP(S), writes it to a temp directory, chmods it 0o755, and execs it detached with windowsHide and unref(). Two independent dropper IIFEs are present in the same file, each with its own decoder and download→write→spawn pipeline, increasing reliability. Any developer or build pipeline that requires or installs this package automatically runs attacker-controlled code with persistence beyond the npm process.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-010977",
            "import_time": "2026-08-04T21:33:12.020828822Z",
            "modified_time": "2026-08-04T21:11:48Z",
            "sha256": "416d6cd82361af6b046d895f23d5e82a82db236a104726914595c21288e33ed0",
            "source": "amazon-inspector",
            "versions": [
                "2.7.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dexwilt/node-fetch

Package

Name
@dexwilt/node-fetch
View open source insights on deps.dev
Purl
pkg:npm/%40dexwilt/node-fetch

Affected ranges

Affected versions

2.*
2.7.3

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "lib/index.js",
            "sha256": "424b4a64884219d678397ef07dc45e0f972819c90ce0faab05c87902d7279415"
        }
    ],
    "package_integrity": [
        {
            "filename": "node-fetch-2.7.3.tgz",
            "hashes": {
                "sha1": "3ae6eb62ade291206fb2a181c06c1c6217e9aa22",
                "sha256": "d44b3b85a41ed3a20b714acb0a9b21376ad2759171f6d8cee7cd5a4433994ae3",
                "sha512_sri": "sha512-HXZfNI0k1FQypo1PVpg+fDxpUxNFTq0Dz3T+5Gq/7WrU+vfMq6pAooIOd9dCKwppkCFWBBiM4+V8n15N5Agopg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dexwilt/node-fetch/MAL-2026-11203.json"