VDB
KO

MAL-2026-11203

Malicious code in @dexwilt/node-fetch (npm)

Details

The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.

Agent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @dexwilt/node-fetch

No fixed version published yet for @dexwilt/node-fetch (npm). Pin to a known-safe version or switch to an alternative.

References