Live tracker
Malicious and suspicious packages
Package versions where Togoder Security's AI source review found dangerous or risky code, newest first. 384 of 1,917 scanned versions have findings at medium severity or above. Last updated Oct 6, 2026.
| Package | Version | Top finding | Scanned |
|---|---|---|---|
| zod | 4.6.5 | Dynamic code execution | Oct 6, 2026 |
| promzard | 3.0.1 | Dynamic code execution | Oct 6, 2026 |
| npm-audit-report | 7.0.0 | Logic error / incorrect severity comparison | Oct 6, 2026 |
| @emnapi/wasi-threads | 1.2.3 | Dynamic code execution | Oct 6, 2026 |
| golang.org/x/sys | v0.48.0 | Feature detection bypass / forced capability enablement | Oct 5, 2026 |
| github.com/bytedance/sonic/loader | v0.5.2 | Dynamic code execution and memory manipulation | Oct 5, 2026 |
| golang.org/x/crypto | v0.57.0 | dangerous_default_deprecation | Oct 5, 2026 |
| @cspotcode/source-map-support | 0.8.1 | Code that runs at install time | Oct 4, 2026 |
Nothing at this level yet.
| Package | Version | Top finding | Scanned |
|---|---|---|---|
| yargs | 18.0.0 | Dynamic module loading with external input | Oct 6, 2026 |
| vitest | 5.0.3 | Potential for code injection | Oct 6, 2026 |
| yargs-parser | 22.0.0 | Dynamic module loading with external input | Oct 6, 2026 |
| yaml | 2.9.0 | Dynamic import with user-controlled path | Oct 6, 2026 |
| why-is-node-running | 3.2.1 | Spawning processes | Oct 6, 2026 |
| web-worker | 1.2.0 | Dynamic code execution | Oct 6, 2026 |
| vite | 8.3.2 | Dynamic code execution | Oct 6, 2026 |
| update-browserslist-db | 1.3.3 | Spawning processes or shell commands | Oct 6, 2026 |
| unrs-resolver | 1.12.2 | Dynamic module loading from environment variable | Oct 6, 2026 |
| lightningcss | 1.33.0 | Dynamic import with computed module name | Oct 6, 2026 |
| undici | 7.29.0 | Potential path traversal / unsafe filename handling | Oct 6, 2026 |
| uglify-js | 3.19.3 | dynamic code execution | Oct 6, 2026 |
| tsconfig-paths | 3.15.0 | Dynamic require with user-controlled path | Oct 6, 2026 |
| rolldown | 1.2.11 | Dynamic import with external input | Oct 6, 2026 |
| typescript | 6.0.3 | Process Spawning and Shell Command Execution | Oct 6, 2026 |
| unicorn-magic | 0.3.0 | Process execution utilities exported | Oct 6, 2026 |
| tunnel | 0.0.6 | Dynamic module loading | Oct 6, 2026 |
| tinyexec | 1.3.0 | Process Spawning | Oct 6, 2026 |
| styled-jsx | 5.1.6 | dangerouslySetInnerHTML usage | Oct 6, 2026 |
| tapable | 2.3.3 | Dynamic code execution | Oct 6, 2026 |
| tar | 7.5.22 | Filesystem traversal via cwd option | Oct 6, 2026 |
| semantic-release | 25.0.9 | Dynamic import based on configuration | Oct 6, 2026 |
| string.prototype.repeat | 1.0.0 | Dynamic module loading / import-time code execution | Oct 6, 2026 |
| string.prototype.trimstart | 1.0.8 | Indirect code execution via module import | Oct 6, 2026 |
| string.prototype.trimend | 1.0.9 | Indirect code execution via module import | Oct 6, 2026 |
| string.prototype.trim | 1.2.10 | Indirect code execution via module import | Oct 6, 2026 |
| sharp | 0.35.5 | Spawn with shell enabled | Oct 6, 2026 |
| string.prototype.includes | 2.0.1 | Dynamic module loading / import-time side effect | Oct 6, 2026 |
| string.prototype.matchall | 4.1.0 | Indirect code execution via module import | Oct 6, 2026 |
| source-map-js | 1.2.1 | dynamic code execution | Oct 6, 2026 |
| resolve-from | 5.0.0 | Dynamic module loading with computed input | Oct 6, 2026 |
| resolve-from | 4.0.0 | Dynamic module resolution using internal Node.js API | Oct 6, 2026 |
| registry-auth-token | 5.1.1 | credential harvesting | Oct 6, 2026 |
| require-from-string | 2.0.2 | Dynamic code execution | Oct 6, 2026 |
| regexp.prototype.flags | 1.5.4 | Indirect code execution via module import | Oct 6, 2026 |
| reflect.getprototypeof | 1.0.10 | Indirect code execution via module import | Oct 6, 2026 |
| unicorn-magic | 0.4.0 | Process execution utilities exported | Oct 6, 2026 |
| prettier | 3.9.9 | Dynamic module loading with computed input | Oct 6, 2026 |
| react | 19.3.0 | Code runs at import time | Oct 6, 2026 |
| prettier-plugin-tailwindcss | 0.8.1 | dynamic-import-with-computed-input | Oct 6, 2026 |
| preact | 10.29.8 | debug/development tooling | Oct 6, 2026 |
| proto-list | 1.2.4 | Prototype pollution | Oct 6, 2026 |
| postcss | 8.5.28 | Prototype manipulation via __proto__ assignment | Oct 6, 2026 |
| orval | 8.39.0 | dynamic import | Oct 6, 2026 |
| openid-client | 5.7.1 | Potential SSRF via JWKS URI | Oct 6, 2026 |
| oauth | 0.9.15 | Hardcoded session secret | Oct 6, 2026 |
| tar | 7.5.19 | Filesystem traversal via cwd option | Oct 6, 2026 |
| object.assign | 4.1.7 | Indirect code execution via module import | Oct 6, 2026 |
| object.values | 1.2.1 | Indirect code execution via module import | Oct 6, 2026 |
| object.groupby | 1.0.3 | Indirect code execution via module import | Oct 6, 2026 |
| object.fromentries | 2.0.8 | Indirect code execution via module import | Oct 6, 2026 |
| object.entries | 1.1.9 | Indirect code execution via module import | Oct 6, 2026 |
| undici | 6.27.0 | Potential denial of service | Oct 6, 2026 |
| read-cmd-shim | 6.0.0 | regular expression complexity | Oct 6, 2026 |
| signal-exit | 4.1.0 | Process manipulation / global state override | Oct 6, 2026 |
| pacote | 21.5.1 | Lifecycle script execution | Oct 6, 2026 |
| proggy | 4.0.0 | Global process event listener manipulation | Oct 6, 2026 |
| node-gyp | 12.4.0 | process_spawning | Oct 6, 2026 |
| libnpmversion | 8.0.4 | Process spawning / shell command execution | Oct 6, 2026 |
| make-fetch-happen | 15.0.6 | Environment Variable Usage | Oct 6, 2026 |
| libnpmpack | 9.1.12 | Lifecycle Script Execution | Oct 6, 2026 |
| libnpmexec | 10.3.2 | Shell command execution | Oct 6, 2026 |
| just-diff | 6.0.2 | dynamic module loading with external input | Oct 6, 2026 |
| just-diff-apply | 5.5.0 | dynamic module loading with external input | Oct 6, 2026 |
| jsonparse | 1.3.1 | credential handling | Oct 6, 2026 |
| bin-links | 6.0.2 | File system manipulation | Oct 6, 2026 |
| @sigstore/sign | 4.1.1 | Environment variable harvesting | Oct 6, 2026 |
| @npmcli/run-script | 10.0.4 | Dynamic module resolution | Oct 6, 2026 |
| @sigstore/verify | 3.1.1 | Unanchored Regular Expression Matching | Oct 6, 2026 |
| @npmcli/promise-spawn | 9.0.1 | Command execution with shell | Oct 6, 2026 |
| @sigstore/tuf | 4.0.2 | Legitimate platform-specific path resolution | Oct 6, 2026 |
| @npmcli/git | 7.0.2 | Spawning processes or shell commands | Oct 6, 2026 |
| @npmcli/config | 10.12.0 | Environment variable harvesting | Oct 6, 2026 |
| @npmcli/arborist | 9.9.1 | Dynamic module loading with computed input | Oct 6, 2026 |
| npm | 11.19.0 | Dynamic module loading with computed input | Oct 6, 2026 |
| @npmcli/fs | 5.0.0 | File system manipulation outside package scope | Oct 6, 2026 |
| @npmcli/agent | 4.0.2 | Environment variable harvesting | Oct 6, 2026 |
| node-addon-api | 7.1.1 | Filesystem Modification | Oct 6, 2026 |
| node-gyp | 13.1.0 | Spawning processes and shell commands | Oct 6, 2026 |
| postcss | 8.5.23 | Path Traversal Risk in Source Map Loading | Oct 6, 2026 |
| next | 16.3.8 | Remote binary download without integrity verification | Oct 6, 2026 |
| next-themes | 0.4.6 | dynamic code execution | Oct 6, 2026 |
| next-intl | 4.14.9 | Dynamic code execution via SWC transform with native plugin | Oct 6, 2026 |
| next-auth | 4.24.15 | Prototype Pollution | Oct 6, 2026 |
| lucide-react | 1.50.0 | Malformed data structure | Oct 6, 2026 |
| napi-postinstall | 0.3.4 | Shell command execution with string interpolation | Oct 6, 2026 |
| mz | 2.7.0 | Sensitive module re-export | Oct 6, 2026 |
| minizlib | 3.1.0 | Private/internal Node.js API access | Oct 6, 2026 |
| marked | 15.0.12 | Dynamic code execution via config file loading | Oct 6, 2026 |
| meow | 13.2.0 | Potential data exfiltration via process.exit and console output | Oct 6, 2026 |
| make-asynchronous | 1.0.1 | Dynamic code execution | Oct 6, 2026 |
| lodash-es | 4.18.1 | Dynamic code execution | Oct 6, 2026 |
| lightningcss | 1.32.0 | Dynamic import with computed module name | Oct 6, 2026 |
| undici | 8.11.2 | Potential path traversal / unsafe filename handling | Oct 6, 2026 |
| json5 | 1.0.2 | Module system modification | Oct 6, 2026 |
| jsdom | 30.1.1 | Dynamic code execution | Oct 6, 2026 |
| jose | 4.15.9 | Insecure JWT implementation (algorithm: none) | Oct 6, 2026 |
| jiti | 2.7.0 | Dynamic import with computed path | Oct 6, 2026 |
| java-properties | 1.0.2 | File system access | Oct 6, 2026 |
| husky | 9.1.7 | File system manipulation outside package scope | Oct 6, 2026 |
About this list
What counts as a malicious npm package?
A package that does something its users did not ask for and would not agree to: running code at install time to steal tokens or environment variables, sending data to an attacker's server, opening a backdoor, mining cryptocurrency or swapping wallet addresses.
Are all packages on this list malware?
No. Critical findings describe dangerous or likely malicious behavior. High and medium findings flag risky patterns, such as dynamic code execution or disabled TLS checks, that are common in legitimate packages and need human review.
How are packages added to the tracker?
Every package scanned with Togoder Security, by anyone, is reviewed file by file by an AI model. Versions whose review produced critical, high or medium findings appear here automatically.
How do I check my own project for malicious packages?
Upload your package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock or another lockfile at https://security.togoder.click/scan. Parsing and the price quote are free, and files that were already reviewed cost nothing.