# node-fetch-native@1.6.7 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T21:17:58.000Z
- Files reviewed: 16
- Findings: 10 low severity findings
- Report: https://security.togoder.click/npm/node-fetch-native
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package node-fetch-native@1.6.7 on Oct 4, 2026. An AI review of 16 source files produced 10 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Data exfiltration

Finding ID: `NPS-783808183946`

File: `dist/chunks/multipart-parser.mjs`

No external network requests or data exfiltration were found in the code. All network-related imports (node:http, node:https, etc.) are standard Node.js modules but are not used for exfiltration.

### [low] Environment variable and credential harvesting

Finding ID: `NPS-12EFA1F372E3`

File: `dist/chunks/multipart-parser.mjs`

No environment variable or credential harvesting patterns (e.g., .npmrc, .pypirc, .ssh, .aws) were detected. The code only deals with multipart parsing.

### [low] Obfuscated code, encoded payloads, or dynamic code execution

Finding ID: `NPS-D0F0A6D49D86`

File: `dist/chunks/multipart-parser.mjs`

No eval, exec, new Function, or obfuscated code was found. The code is minified but not obfuscated beyond normal bundling.

### [low] Cryptocurrency mining or wallet drainers

Finding ID: `NPS-A917995A6FD7`

File: `dist/chunks/multipart-parser.mjs`

No cryptocurrency mining or wallet-related code was found.

### [low] Backdoor installation or reverse shells

Finding ID: `NPS-8E75357E6C84`

File: `dist/chunks/multipart-parser.mjs`

No backdoor or reverse shell patterns were detected.

### [low] Code that runs at install, build or import time

Finding ID: `NPS-A4A780A7B3ED`

File: `dist/chunks/multipart-parser.mjs`

The module does not execute any suspicious code at import time. It defines and exports a function (toFormData) and imports necessary modules.

### [low] Suspicious network requests

Finding ID: `NPS-34D6706838B0`

File: `dist/chunks/multipart-parser.mjs`

No suspicious network requests were found. The code does not perform any network operations directly.

### [low] File system manipulation outside package scope

Finding ID: `NPS-88F43450A310`

File: `dist/chunks/multipart-parser.mjs`

No file system manipulation was detected. The code does not use fs to read/write files.

### [low] Spawning processes or shell commands

Finding ID: `NPS-557686FAE0A3`

File: `dist/chunks/multipart-parser.mjs`

No child_process or shell command execution was found.

### [low] Dynamic imports or module loading with computed or external input

Finding ID: `NPS-7E56FE916D8D`

File: `dist/chunks/multipart-parser.mjs`

No dynamic imports or module loading with computed input were detected.

## Files reviewed

- `dist/chunks/multipart-parser.cjs` (safe): No malicious patterns detected; the code is a standard multipart/form-data parser for handling HTTP requests.
- `dist/chunks/multipart-parser.mjs` (safe): The code is a multipart parser with no malicious patterns detected; it appears safe for use.
- `dist/index.cjs` (safe): No malicious patterns detected; the code is a standard entry point for a fetch polyfill that exports native or fallback implementations of fetch and related web APIs without any suspicious behavior.
- `dist/index.mjs` (safe): No malicious patterns detected; the file is a simple conditional polyfill loader for fetch APIs using Node.js built-ins and local shared modules.
- `dist/native.cjs` (safe): No malicious patterns detected; the code only re-exports standard Web APIs and a fetch polyfill without obfuscation, network exfiltration, filesystem access, or dynamic execution.
- `dist/native.mjs` (safe): This file is a simple re-export shim for global fetch/Web API classes with no malicious patterns or suspicious behavior.
- `dist/polyfill.cjs` (safe): No malicious patterns detected; the file is a standard polyfill that conditionally assigns global fetch/Blob/File/etc. from the node-fetch-native package without any suspicious activity.
- `dist/polyfill.mjs` (safe): No malicious patterns detected; the code is a standard polyfill for Node.js globals (fetch, Blob, File, FormData, Headers, Request, Response, AbortController) that conditionally assigns them to globalThis.
- `dist/proxy-stub.cjs` (safe): No malicious patterns detected
- `dist/proxy-stub.mjs` (safe): No malicious patterns detected
- `dist/shared/node-fetch-native.DfbY2q-x.mjs` (safe): No malicious patterns detected
- `dist/shared/node-fetch-native.DhEqb06g.cjs` (safe): No malicious patterns detected
- `lib/empty.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/empty.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.cjs` (safe): The file is a thin wrapper that re-exports an internal fetch implementation without any malicious patterns.
- `lib/native.cjs` (safe): No malicious patterns detected; the file is a simple wrapper re-exporting the native fetch implementation from a local dist module.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
