Analyze your own packages withvet GitHub

@better-fetch/fetch@1.1.18

Safe
Analyzed at:3/26/2025, 6:31:06 PM
Source:https://registry.npmjs.org/@better-fetch/fetch/-/fetch-1.1.18.tgz
SHA256:24c8ce8245a3ab29823f92232bfce9277acd5afaeed3ae1767387365c12c48dc
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Insufficient evidence to classify as malware. Missing source info is not conclusive proof of malicious intent.

Details

Based on the provided evidence, there is insufficient information to classify @better-fetch/fetch version 1.1.18 as malware. Evidence 0 indicates a lack of source project information. This is not inherently malicious; newly published packages or those from private repositories may lack this information. The absence of further evidence (e.g., LLM analysis of package contents, suspicious network activity, or malicious code identified by static analysis) prevents a definitive malware classification. The low confidence level of the existing evidence reinforces the need for more comprehensive analysis before a conclusion can be drawn.