Summary
Togoder Security scanned the npm package node-fetch-native@1.6.7 on Oct 4, 2026. An AI review of 16 source files produced 10 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 10
Data exfiltration
NPS-783808183946
No external network requests or data exfiltration were found in the code. All network-related imports (node:http, node:https, etc.) are standard Node.js modules but are not used for exfiltration.
Environment variable and credential harvesting
NPS-12EFA1F372E3
No environment variable or credential harvesting patterns (e.g., .npmrc, .pypirc, .ssh, .aws) were detected. The code only deals with multipart parsing.
Obfuscated code, encoded payloads, or dynamic code execution
NPS-D0F0A6D49D86
No eval, exec, new Function, or obfuscated code was found. The code is minified but not obfuscated beyond normal bundling.
Cryptocurrency mining or wallet drainers
NPS-A917995A6FD7
No cryptocurrency mining or wallet-related code was found.
Backdoor installation or reverse shells
NPS-8E75357E6C84
No backdoor or reverse shell patterns were detected.
Code that runs at install, build or import time
NPS-A4A780A7B3ED
The module does not execute any suspicious code at import time. It defines and exports a function (toFormData) and imports necessary modules.
Suspicious network requests
NPS-34D6706838B0
No suspicious network requests were found. The code does not perform any network operations directly.
File system manipulation outside package scope
NPS-88F43450A310
No file system manipulation was detected. The code does not use fs to read/write files.
Spawning processes or shell commands
NPS-557686FAE0A3
No child_process or shell command execution was found.
Dynamic imports or module loading with computed or external input
NPS-7E56FE916D8D
No dynamic imports or module loading with computed input were detected.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/chunks/multipart-parser.cjs | safe | No malicious patterns detected; the code is a standard multipart/form-data parser for handling HTTP requests. |
| dist/chunks/multipart-parser.mjs | safe | The code is a multipart parser with no malicious patterns detected; it appears safe for use. |
| dist/index.cjs | safe | No malicious patterns detected; the code is a standard entry point for a fetch polyfill that exports native or fallback implementations of fetch and related web APIs without any suspicious behavior. |
| dist/index.mjs | safe | No malicious patterns detected; the file is a simple conditional polyfill loader for fetch APIs using Node.js built-ins and local shared modules. |
| dist/native.cjs | safe | No malicious patterns detected; the code only re-exports standard Web APIs and a fetch polyfill without obfuscation, network exfiltration, filesystem access, or dynamic execution. |
| dist/native.mjs | safe | This file is a simple re-export shim for global fetch/Web API classes with no malicious patterns or suspicious behavior. |
| dist/polyfill.cjs | safe | No malicious patterns detected; the file is a standard polyfill that conditionally assigns global fetch/Blob/File/etc. from the node-fetch-native package without any suspicious activity. |
| dist/polyfill.mjs | safe | No malicious patterns detected; the code is a standard polyfill for Node.js globals (fetch, Blob, File, FormData, Headers, Request, Response, AbortController) that conditionally assigns them to globalThis. |
| dist/proxy-stub.cjs | safe | No malicious patterns detected |
| dist/proxy-stub.mjs | safe | No malicious patterns detected |
| dist/shared/node-fetch-native.DfbY2q-x.mjs | safe | No malicious patterns detected |
| dist/shared/node-fetch-native.DhEqb06g.cjs | safe | No malicious patterns detected |
| lib/empty.cjs | safe | Cleared by Jev triage; no further analysis needed |
| lib/empty.mjs | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.cjs | safe | The file is a thin wrapper that re-exports an internal fetch implementation without any malicious patterns. |
| lib/native.cjs | safe | No malicious patterns detected; the file is a simple wrapper re-exporting the native fetch implementation from a local dist module. |
Frequently asked questions
Is node-fetch-native safe to use?
Our AI source review of node-fetch-native@1.6.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does node-fetch-native contain malware?
No malware was identified in node-fetch-native@1.6.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was node-fetch-native checked?
Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan node-fetch-native together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-fetch-native@1.6.7, cost nothing.