Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@dexwilt/node-fetchnpm

@dexwilt/node-fetch is a confirmed malicious npm package (MAL-2026-11203) that typosquats a legitimate package to trick installs (malicious version 2.7.3). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @dexwilt/node-fetch (npm)

MAL-2026-11203
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @dexwilt/node-fetch

What this malware does

The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.

Agent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.

Malicious versions

1 flagged
2.7.3

Detection & response playbook

Typosquat
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @dexwilt/node-fetch (version 2.7.3). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @dexwilt/node-fetch across your stack and pipelines.

  2. If you installed it — respond

    @dexwilt/node-fetch is a typosquat — you almost certainly intended a legitimately-named package. Remove @dexwilt/node-fetch, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If @dexwilt/node-fetch was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @dexwilt/node-fetch before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @dexwilt/node-fetch on npm has been identified as a malicious package (version 2.7.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

References

Credits

  • YoSheep · finder

Detect & block this

O3 blocks @dexwilt/node-fetch-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

@dexwilt/node-fetch (npm) malicious package — MAL-2026-11203 | O3 Security