# make-fetch-happen@15.0.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:23.000Z
- Files reviewed: 10
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/make-fetch-happen
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package make-fetch-happen@15.0.6 on Oct 6, 2026. An AI review of 10 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Potential Prototype Pollution / Unvalidated Options

Finding ID: `NPS-65CD61218288`

File: `lib/options.js:13`

The function spreads user-provided opts into a new object and then modifies it. While it uses object spread (safe), it does not validate the structure of nested objects like options.retry, options.dns, or options.headers. An attacker could potentially pass malicious objects that could cause unexpected behavior, though no direct code execution is present.

### [low] Environment Variable Usage

Finding ID: `NPS-7BCF3C846F31`

File: `lib/options.js:17`

The code reads process.env.NODE_TLS_REJECT_UNAUTHORIZED to determine TLS certificate validation behavior. While this is a standard Node.js environment variable, its use here could allow an attacker to disable TLS verification by setting NODE_TLS_REJECT_UNAUTHORIZED=0, potentially enabling man-in-the-middle attacks. This is not malicious per se, but it's a security-sensitive environment variable read.

## Files reviewed

- `lib/options.js` (medium): The code appears to be a legitimate HTTP request option configuration utility with no malicious patterns, though it reads a security-sensitive environment variable and lacks strict input validation.
- `lib/cache/entry.js` (safe): This is a legitimate HTTP cache implementation (likely from npm's make-fetch-happen package); no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution were detected.
- `lib/cache/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cache/index.js` (safe): No malicious patterns detected
- `lib/cache/key.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cache/policy.js` (safe): No malicious patterns detected; the code is a standard HTTP cache policy implementation using http-cache-semantics and related libraries.
- `lib/fetch.js` (safe): The code is a legitimate HTTP fetch implementation with redirect handling and cache integration, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
- `lib/index.js` (safe): No malicious patterns detected
- `lib/pipeline.js` (safe): The code is a legitimate wrapper around minipass-pipeline that caches specified events, with no malicious patterns detected.
- `lib/remote.js` (safe): No malicious patterns detected; the code implements a standard HTTP fetch wrapper with retry, redirect, and integrity verification logic for an npm-related package.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
