Togoder security

npm package security report

node-fetch-native npm package: is it safe?

No malicious code found.

No issues Version 1.6.7 Files reviewed 16 Size 702.2 KB Scanned

Summary

Togoder Security scanned the npm package node-fetch-native@1.6.7 on Oct 4, 2026. An AI review of 16 source files produced 10 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
10
low

Findings 10

low

Data exfiltration

NPS-783808183946

No external network requests or data exfiltration were found in the code. All network-related imports (node:http, node:https, etc.) are standard Node.js modules but are not used for exfiltration.

dist/chunks/multipart-parser.mjs
low

Environment variable and credential harvesting

NPS-12EFA1F372E3

No environment variable or credential harvesting patterns (e.g., .npmrc, .pypirc, .ssh, .aws) were detected. The code only deals with multipart parsing.

dist/chunks/multipart-parser.mjs
low

Obfuscated code, encoded payloads, or dynamic code execution

NPS-D0F0A6D49D86

No eval, exec, new Function, or obfuscated code was found. The code is minified but not obfuscated beyond normal bundling.

dist/chunks/multipart-parser.mjs
low

Cryptocurrency mining or wallet drainers

NPS-A917995A6FD7

No cryptocurrency mining or wallet-related code was found.

dist/chunks/multipart-parser.mjs
low

Backdoor installation or reverse shells

NPS-8E75357E6C84

No backdoor or reverse shell patterns were detected.

dist/chunks/multipart-parser.mjs
low

Code that runs at install, build or import time

NPS-A4A780A7B3ED

The module does not execute any suspicious code at import time. It defines and exports a function (toFormData) and imports necessary modules.

dist/chunks/multipart-parser.mjs
low

Suspicious network requests

NPS-34D6706838B0

No suspicious network requests were found. The code does not perform any network operations directly.

dist/chunks/multipart-parser.mjs
low

File system manipulation outside package scope

NPS-88F43450A310

No file system manipulation was detected. The code does not use fs to read/write files.

dist/chunks/multipart-parser.mjs
low

Spawning processes or shell commands

NPS-557686FAE0A3

No child_process or shell command execution was found.

dist/chunks/multipart-parser.mjs
low

Dynamic imports or module loading with computed or external input

NPS-7E56FE916D8D

No dynamic imports or module loading with computed input were detected.

dist/chunks/multipart-parser.mjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/chunks/multipart-parser.cjs safe No malicious patterns detected; the code is a standard multipart/form-data parser for handling HTTP requests.
dist/chunks/multipart-parser.mjs safe The code is a multipart parser with no malicious patterns detected; it appears safe for use.
dist/index.cjs safe No malicious patterns detected; the code is a standard entry point for a fetch polyfill that exports native or fallback implementations of fetch and related web APIs without any suspicious behavior.
dist/index.mjs safe No malicious patterns detected; the file is a simple conditional polyfill loader for fetch APIs using Node.js built-ins and local shared modules.
dist/native.cjs safe No malicious patterns detected; the code only re-exports standard Web APIs and a fetch polyfill without obfuscation, network exfiltration, filesystem access, or dynamic execution.
dist/native.mjs safe This file is a simple re-export shim for global fetch/Web API classes with no malicious patterns or suspicious behavior.
dist/polyfill.cjs safe No malicious patterns detected; the file is a standard polyfill that conditionally assigns global fetch/Blob/File/etc. from the node-fetch-native package without any suspicious activity.
dist/polyfill.mjs safe No malicious patterns detected; the code is a standard polyfill for Node.js globals (fetch, Blob, File, FormData, Headers, Request, Response, AbortController) that conditionally assigns them to globalThis.
dist/proxy-stub.cjs safe No malicious patterns detected
dist/proxy-stub.mjs safe No malicious patterns detected
dist/shared/node-fetch-native.DfbY2q-x.mjs safe No malicious patterns detected
dist/shared/node-fetch-native.DhEqb06g.cjs safe No malicious patterns detected
lib/empty.cjs safe Cleared by Jev triage; no further analysis needed
lib/empty.mjs safe Cleared by Jev triage; no further analysis needed
lib/index.cjs safe The file is a thin wrapper that re-exports an internal fetch implementation without any malicious patterns.
lib/native.cjs safe No malicious patterns detected; the file is a simple wrapper re-exporting the native fetch implementation from a local dist module.

Scanned versions of node-fetch-native

VersionVerdictFilesScanned
1.6.7 No issues 16 Oct 4, 2026

Frequently asked questions

Is node-fetch-native safe to use?

Our AI source review of node-fetch-native@1.6.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does node-fetch-native contain malware?

No malware was identified in node-fetch-native@1.6.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was node-fetch-native checked?

Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan node-fetch-native together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-fetch-native@1.6.7, cost nothing.

Related security reports