🛡️ MAL-2026-11203 — node-fetch
Description
Malicious code in @dexwilt/node-fetch (npm)
The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.
Agent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.
Source: amazon-inspector
@dexwilt/node-fetch impersonates the popular node-fetch package under a personal scope. Its main entrypoint (lib/index.js, lib/index.mjs, lib/index.es.js) ships the legitimate node-fetch v2 source with two appended, heavily obfuscated self-executing IIFEs that contain RC4+base64 string-array decoders reconstructing calls to https.request, fs.writeFileSync, fs.chmodSync, and child_process.spawn. Execution is gated on process.env.npm_config_user_agent — set by npm/yarn/pnpm during install but absent in plain node/REPL runs — so the payload only fires inside real installs while staying dormant during casual inspection. When triggered, the code re-spawns the current Node process detached with stdio ignored, downloads a remote binary over HTTP(S), writes it to a temp directory, chmods it 0o755, and execs it detached with windowsHide and unref(). Two independent dropper IIFEs are present in the same file, each with its own decoder and download→write→spawn pipeline, increasing reliability. Any developer or build pipeline that requires or installs this package automatically runs attacker-controlled code with persistence beyond the npm process.
Affected software
MAL-2026-11203 is recorded against 1 package.
- @dexwilt/node-fetch
Timeline and source
Published on 22 June 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.npmjs.com (Web)
github.com (Report)
www.npmjs.com (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| @dexwilt/node-fetch | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-11203?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-11203 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.