paper-fetch
Audited by Socket on Aug 19, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The core PDF-fetching purpose is coherent, and most API/data flows are expected, but the default Sci-Hub fallback, mirror scraping, and optional stealth-browser Cloudflare bypass expand the skill beyond a standard scholarly fetcher. This is not confirmed malware, yet its network behavior and third-party routing create elevated legal, trust, and supply-chain risk.
The module is best characterized as a stealth/headless browser-based ‘challenge-aware’ remote fetcher that performs an in-page JavaScript evaluation to obtain base64-encoded content and streams the decoded bytes to stdout. It includes meaningful SSRF-style protections (blocks localhost/private/cloud-metadata IP ranges), but the key behavior is delegated to the unseen _FETCH_JS, which is a high-impact unknown. No explicit credential theft or direct system compromise is visible in the Python fragment, yet the challenge-bypass design and raw byte output make it plausibly risky for unauthorized content retrieval depending on how _FETCH_JS fetches/redirects and how callers use the output.