PkgRadar

Malware advisory

MAL-2026-11203

Malicious code in @dexwilt/node-fetch (npm)

1 affected release in the PkgRadar corpus · published 2026-06-22 · upstream advisory

Affected packages

PackageEcosystemVersionVerdictScanned (UTC)
@dexwilt/node-fetchnpm2.7.3High risk2026-07-31

PkgRadar blocks these releases at the CI gate before they reach your build. Start free or see all advisories.

MAL-2026-11203 — malicious package advisory | PkgRadar