Togoder security

npm package security report

make-fetch-happen npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 15.0.6 Files reviewed 10 Size 35.4 KB Scanned

Summary

Togoder Security scanned the npm package make-fetch-happen@15.0.6 on Oct 6, 2026. An AI review of 10 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

Potential Prototype Pollution / Unvalidated Options

NPS-65CD61218288

The function spreads user-provided opts into a new object and then modifies it. While it uses object spread (safe), it does not validate the structure of nested objects like options.retry, options.dns, or options.headers. An attacker could potentially pass malicious objects that could cause unexpected behavior, though no direct code execution is present.

lib/options.js:13
low

Environment Variable Usage

NPS-7BCF3C846F31

The code reads process.env.NODE_TLS_REJECT_UNAUTHORIZED to determine TLS certificate validation behavior. While this is a standard Node.js environment variable, its use here could allow an attacker to disable TLS verification by setting NODE_TLS_REJECT_UNAUTHORIZED=0, potentially enabling man-in-the-middle attacks. This is not malicious per se, but it's a security-sensitive environment variable read.

lib/options.js:17

Files reviewed

FileVerdictWhat the reviewer saw
lib/options.js medium The code appears to be a legitimate HTTP request option configuration utility with no malicious patterns, though it reads a security-sensitive environment variable and lacks strict input validation.
lib/cache/entry.js safe This is a legitimate HTTP cache implementation (likely from npm's make-fetch-happen package); no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution were detected.
lib/cache/errors.js safe Cleared by Jev triage; no further analysis needed
lib/cache/index.js safe No malicious patterns detected
lib/cache/key.js safe Cleared by Jev triage; no further analysis needed
lib/cache/policy.js safe No malicious patterns detected; the code is a standard HTTP cache policy implementation using http-cache-semantics and related libraries.
lib/fetch.js safe The code is a legitimate HTTP fetch implementation with redirect handling and cache integration, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
lib/index.js safe No malicious patterns detected
lib/pipeline.js safe The code is a legitimate wrapper around minipass-pipeline that caches specified events, with no malicious patterns detected.
lib/remote.js safe No malicious patterns detected; the code implements a standard HTTP fetch wrapper with retry, redirect, and integrity verification logic for an npm-related package.

Scanned versions of make-fetch-happen

VersionVerdictFilesScanned
15.0.6 Needs review 10 Oct 6, 2026

Frequently asked questions

Is make-fetch-happen safe to use?

No confirmed malware was found in make-fetch-happen@15.0.6, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does make-fetch-happen contain malware?

No malware was identified in make-fetch-happen@15.0.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was make-fetch-happen checked?

Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan make-fetch-happen together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in make-fetch-happen@15.0.6, cost nothing.

Related security reports