{"id":"MAL-2026-11203","summary":"Malicious code in @dexwilt/node-fetch (npm)","details":"The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.\n\nAgent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.","modified":"2026-07-31T00:06:14.477165218Z","published":"2026-06-22T10:44:41Z","references":[{"type":"WEB","url":"https://www.npmjs.com/package/@dexwilt/node-fetch/v/2.7.3"},{"type":"REPORT","url":"https://github.com/ossf/malicious-packages/issues/1373"}],"affected":[{"package":{"name":"@dexwilt/node-fetch","ecosystem":"npm","purl":"pkg:npm/%40dexwilt/node-fetch"},"versions":["2.7.3"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"424b4a64884219d678397ef07dc45e0f972819c90ce0faab05c87902d7279415","path":"lib/index.js"}],"package_integrity":[{"hashes":{"sha256":"d44b3b85a41ed3a20b714acb0a9b21376ad2759171f6d8cee7cd5a4433994ae3","sha512_sri":"sha512-HXZfNI0k1FQypo1PVpg+fDxpUxNFTq0Dz3T+5Gq/7WrU+vfMq6pAooIOd9dCKwppkCFWBBiM4+V8n15N5Agopg==","sha1":"3ae6eb62ade291206fb2a181c06c1c6217e9aa22"},"filename":"node-fetch-2.7.3.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dexwilt/node-fetch/MAL-2026-11203.json"}}],"schema_version":"1.7.5","credits":[{"name":"YoSheep","contact":["https://github.com/YoSheep"],"type":"FINDER"}]}