node-fetch-core@1.0.0
Malicious code in node-fetch-core (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1564.001 · Hidden Files and Directories
Analysis
node-fetch-core@1.0.0 combosquats the popular node-fetch package. Its preinstall hook (node install.js) runs execSync to curl a second-stage payload from a raw GitHub gist (gist[.]githubusercontent[.]com/p1g3/888a...), saves it to /Library/Caches/com.apple.act.mond (a disguised, persistent macOS cache path), chmods it executable, and executes it — all wrapped in a silent catch block to avoid alarming the installer. This is a first-stage dropper; the gist-hosted payload is the actual malicious component retrieved at runtime.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:57 AM
- analyzed
- Jun 11, 2026, 12:04 PM
Related advisories
- node-denv@1.3.5
- vite-config-optimizer@1.1.4
- dolyame-boxy-atom-bnpl-navigation-arrow@35.6.5
- devplatform-spa-plugin-s3-module-loader@35.8.2
- bigops-create-manifest@35.2.4
- bigops-cobrowsing@35.4.9
- terminal-kit-tslint-config@20.1.9
- twork-data-services-aggregator-sme-task-info@20.3.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.