logo

Supply Chain Phishing Campaign Drops More Malware Into NPM: got-fetch 5.1

ID: b982b114-df08-5760-bb0c-c33ee266b4b6

STIX ID: report--b982b114-df08-5760-bb0c-c33ee266b4b6

Feed Name: Checkmarx Zero

Threat Score
75/100

Date Published: 2025-07-21

Date Updated: 2026-04-27

Author: Tal Folkman

...
...

Checkmarx discovered that npm package got-fetch versions 5.1.11 and 5.1.12 were backdoored after a maintainer was compromised by a phishing campaign; the malicious releases included a Pycoon information-stealer (crashreporter.dll). The maintainer and npm deprecated/removed the versions, but the advisory warns that cached copies in internal registries or deployed containers may persist, provides indicators (package.json/package-lock entries and a malicious DLL hash), lists other affected packages, and gives remediation steps (migrate to Node.js fetch, upgrade/downgrade got-fetch, remove cached/deployed instances, and update detection tools).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.