@dexwilt/node-fetchnpm
@dexwilt/node-fetch is a confirmed malicious npm package (MAL-2026-11203) that typosquats a legitimate package to trick installs (malicious version 2.7.3). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in @dexwilt/node-fetch (npm)
What this malware does
The @dexwilt/node-fetch package impersonates the legitimate node-fetch project: its package metadata copies the upstream repository, author, and homepage while publishing under an unrelated scope. Its CommonJS entry point lib/index.js contains the expected node-fetch implementation followed by approximately 94 KB of additional RC4/Base64-obfuscated code. The ESM builds do not contain this appended payload.
Agent-assisted deobfuscation of the appended payload recovered a cross-platform download and execution chain. It retrieves a remote binary from an encrypted endpoint, records and verifies the downloaded file's SHA-256 value, and starts the binary with detached, hidden-window, and ignored-stdio options before unreferencing the child process. The original obfuscated source independently exposes the detached, windowsHide, stdio, environment, working-directory, size, SHA-256, and download timestamp fields used by this chain. Loading the package's declared main entry point therefore executes a concealed remote payload loader embedded after otherwise legitimate node-fetch code.
Malicious versions
Detection & response playbook
TyposquatFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @dexwilt/node-fetch (version 2.7.3). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @dexwilt/node-fetch across your stack and pipelines.
If you installed it — respond
@dexwilt/node-fetch is a typosquat — you almost certainly intended a legitimately-named package. Remove @dexwilt/node-fetch, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If @dexwilt/node-fetch was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks @dexwilt/node-fetch before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
References
Credits
- YoSheep · finder
Detect & block this
O3 blocks @dexwilt/node-fetch-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.