Summary
Togoder Security scanned the npm package make-fetch-happen@15.0.6 on Oct 6, 2026. An AI review of 10 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Potential Prototype Pollution / Unvalidated Options
NPS-65CD61218288
The function spreads user-provided opts into a new object and then modifies it. While it uses object spread (safe), it does not validate the structure of nested objects like options.retry, options.dns, or options.headers. An attacker could potentially pass malicious objects that could cause unexpected behavior, though no direct code execution is present.
Environment Variable Usage
NPS-7BCF3C846F31
The code reads process.env.NODE_TLS_REJECT_UNAUTHORIZED to determine TLS certificate validation behavior. While this is a standard Node.js environment variable, its use here could allow an attacker to disable TLS verification by setting NODE_TLS_REJECT_UNAUTHORIZED=0, potentially enabling man-in-the-middle attacks. This is not malicious per se, but it's a security-sensitive environment variable read.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/options.js | medium | The code appears to be a legitimate HTTP request option configuration utility with no malicious patterns, though it reads a security-sensitive environment variable and lacks strict input validation. |
| lib/cache/entry.js | safe | This is a legitimate HTTP cache implementation (likely from npm's make-fetch-happen package); no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution were detected. |
| lib/cache/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/cache/index.js | safe | No malicious patterns detected |
| lib/cache/key.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/cache/policy.js | safe | No malicious patterns detected; the code is a standard HTTP cache policy implementation using http-cache-semantics and related libraries. |
| lib/fetch.js | safe | The code is a legitimate HTTP fetch implementation with redirect handling and cache integration, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access. |
| lib/index.js | safe | No malicious patterns detected |
| lib/pipeline.js | safe | The code is a legitimate wrapper around minipass-pipeline that caches specified events, with no malicious patterns detected. |
| lib/remote.js | safe | No malicious patterns detected; the code implements a standard HTTP fetch wrapper with retry, redirect, and integrity verification logic for an npm-related package. |
Scanned versions of make-fetch-happen
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 15.0.6 | Needs review | 10 | Oct 6, 2026 |
Frequently asked questions
Is make-fetch-happen safe to use?
No confirmed malware was found in make-fetch-happen@15.0.6, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does make-fetch-happen contain malware?
No malware was identified in make-fetch-happen@15.0.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was make-fetch-happen checked?
Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan make-fetch-happen together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in make-fetch-happen@15.0.6, cost nothing.