VYPR

npm · Malicious package advisory

Malware

@dexwilt/node-fetch

GHSA-xqj6-r3qp-9rx9

Malicious code in @dexwilt/node-fetch (npm)

Details

**Severity:** Critical

**Affected versions:** `= 2.7.3`

The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.

Agent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/93c874ee0e8a44e3f4e0fcdeab2c87088f7365a8/osv/malicious/npm/@dexwilt/node-fetch/MAL-2026-11203.json))

**References:**
- https://github.com/ossf/malicious-packages/issues/1373
- https://github.com/ossf/malicious-packages/blob/93c874ee0e8a44e3f4e0fcdeab2c87088f7365a8/osv/malicious/npm/@dexwilt/node-fetch/MAL-2026-11203.json
- https://www.npmjs.com/package/@dexwilt/node-fetch/v/2.7.3
- https://github.com/advisories/GHSA-xqj6-r3qp-9rx9

Compromised versions (1)

  • = 2.7.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.