Togoder security

Live tracker

Malicious and suspicious packages

Package versions where Togoder Security's AI source review found dangerous or risky code, newest first. 384 of 1,917 scanned versions have findings at medium severity or above. Last updated Oct 6, 2026.

critical Critical: dangerous or likely malicious 8Code that runs at install time, reads credentials, exfiltrates data or opens a backdoor.
PackageVersionTop findingScanned
zod 4.6.5 Dynamic code execution Oct 6, 2026
promzard 3.0.1 Dynamic code execution Oct 6, 2026
npm-audit-report 7.0.0 Logic error / incorrect severity comparison Oct 6, 2026
@emnapi/wasi-threads 1.2.3 Dynamic code execution Oct 6, 2026
golang.org/x/sys v0.48.0 Feature detection bypass / forced capability enablement Oct 5, 2026
github.com/bytedance/sonic/loader v0.5.2 Dynamic code execution and memory manipulation Oct 5, 2026
golang.org/x/crypto v0.57.0 dangerous_default_deprecation Oct 5, 2026
@cspotcode/source-map-support 0.8.1 Code that runs at install time Oct 4, 2026
high High risk 0Risky behavior that needs review before use.

Nothing at this level yet.

medium Needs review: risky patterns, not malware 100+Common in legitimate packages; listed for transparency.
PackageVersionTop findingScanned
yargs 18.0.0 Dynamic module loading with external input Oct 6, 2026
vitest 5.0.3 Potential for code injection Oct 6, 2026
yargs-parser 22.0.0 Dynamic module loading with external input Oct 6, 2026
yaml 2.9.0 Dynamic import with user-controlled path Oct 6, 2026
why-is-node-running 3.2.1 Spawning processes Oct 6, 2026
web-worker 1.2.0 Dynamic code execution Oct 6, 2026
vite 8.3.2 Dynamic code execution Oct 6, 2026
update-browserslist-db 1.3.3 Spawning processes or shell commands Oct 6, 2026
unrs-resolver 1.12.2 Dynamic module loading from environment variable Oct 6, 2026
lightningcss 1.33.0 Dynamic import with computed module name Oct 6, 2026
undici 7.29.0 Potential path traversal / unsafe filename handling Oct 6, 2026
uglify-js 3.19.3 dynamic code execution Oct 6, 2026
tsconfig-paths 3.15.0 Dynamic require with user-controlled path Oct 6, 2026
rolldown 1.2.11 Dynamic import with external input Oct 6, 2026
typescript 6.0.3 Process Spawning and Shell Command Execution Oct 6, 2026
unicorn-magic 0.3.0 Process execution utilities exported Oct 6, 2026
tunnel 0.0.6 Dynamic module loading Oct 6, 2026
tinyexec 1.3.0 Process Spawning Oct 6, 2026
styled-jsx 5.1.6 dangerouslySetInnerHTML usage Oct 6, 2026
tapable 2.3.3 Dynamic code execution Oct 6, 2026
tar 7.5.22 Filesystem traversal via cwd option Oct 6, 2026
semantic-release 25.0.9 Dynamic import based on configuration Oct 6, 2026
string.prototype.repeat 1.0.0 Dynamic module loading / import-time code execution Oct 6, 2026
string.prototype.trimstart 1.0.8 Indirect code execution via module import Oct 6, 2026
string.prototype.trimend 1.0.9 Indirect code execution via module import Oct 6, 2026
string.prototype.trim 1.2.10 Indirect code execution via module import Oct 6, 2026
sharp 0.35.5 Spawn with shell enabled Oct 6, 2026
string.prototype.includes 2.0.1 Dynamic module loading / import-time side effect Oct 6, 2026
string.prototype.matchall 4.1.0 Indirect code execution via module import Oct 6, 2026
source-map-js 1.2.1 dynamic code execution Oct 6, 2026
resolve-from 5.0.0 Dynamic module loading with computed input Oct 6, 2026
resolve-from 4.0.0 Dynamic module resolution using internal Node.js API Oct 6, 2026
registry-auth-token 5.1.1 credential harvesting Oct 6, 2026
require-from-string 2.0.2 Dynamic code execution Oct 6, 2026
regexp.prototype.flags 1.5.4 Indirect code execution via module import Oct 6, 2026
reflect.getprototypeof 1.0.10 Indirect code execution via module import Oct 6, 2026
unicorn-magic 0.4.0 Process execution utilities exported Oct 6, 2026
prettier 3.9.9 Dynamic module loading with computed input Oct 6, 2026
react 19.3.0 Code runs at import time Oct 6, 2026
prettier-plugin-tailwindcss 0.8.1 dynamic-import-with-computed-input Oct 6, 2026
preact 10.29.8 debug/development tooling Oct 6, 2026
proto-list 1.2.4 Prototype pollution Oct 6, 2026
postcss 8.5.28 Prototype manipulation via __proto__ assignment Oct 6, 2026
orval 8.39.0 dynamic import Oct 6, 2026
openid-client 5.7.1 Potential SSRF via JWKS URI Oct 6, 2026
oauth 0.9.15 Hardcoded session secret Oct 6, 2026
tar 7.5.19 Filesystem traversal via cwd option Oct 6, 2026
object.assign 4.1.7 Indirect code execution via module import Oct 6, 2026
object.values 1.2.1 Indirect code execution via module import Oct 6, 2026
object.groupby 1.0.3 Indirect code execution via module import Oct 6, 2026
object.fromentries 2.0.8 Indirect code execution via module import Oct 6, 2026
object.entries 1.1.9 Indirect code execution via module import Oct 6, 2026
undici 6.27.0 Potential denial of service Oct 6, 2026
read-cmd-shim 6.0.0 regular expression complexity Oct 6, 2026
signal-exit 4.1.0 Process manipulation / global state override Oct 6, 2026
pacote 21.5.1 Lifecycle script execution Oct 6, 2026
proggy 4.0.0 Global process event listener manipulation Oct 6, 2026
node-gyp 12.4.0 process_spawning Oct 6, 2026
libnpmversion 8.0.4 Process spawning / shell command execution Oct 6, 2026
make-fetch-happen 15.0.6 Environment Variable Usage Oct 6, 2026
libnpmpack 9.1.12 Lifecycle Script Execution Oct 6, 2026
libnpmexec 10.3.2 Shell command execution Oct 6, 2026
just-diff 6.0.2 dynamic module loading with external input Oct 6, 2026
just-diff-apply 5.5.0 dynamic module loading with external input Oct 6, 2026
jsonparse 1.3.1 credential handling Oct 6, 2026
bin-links 6.0.2 File system manipulation Oct 6, 2026
@sigstore/sign 4.1.1 Environment variable harvesting Oct 6, 2026
@npmcli/run-script 10.0.4 Dynamic module resolution Oct 6, 2026
@sigstore/verify 3.1.1 Unanchored Regular Expression Matching Oct 6, 2026
@npmcli/promise-spawn 9.0.1 Command execution with shell Oct 6, 2026
@sigstore/tuf 4.0.2 Legitimate platform-specific path resolution Oct 6, 2026
@npmcli/git 7.0.2 Spawning processes or shell commands Oct 6, 2026
@npmcli/config 10.12.0 Environment variable harvesting Oct 6, 2026
@npmcli/arborist 9.9.1 Dynamic module loading with computed input Oct 6, 2026
npm 11.19.0 Dynamic module loading with computed input Oct 6, 2026
@npmcli/fs 5.0.0 File system manipulation outside package scope Oct 6, 2026
@npmcli/agent 4.0.2 Environment variable harvesting Oct 6, 2026
node-addon-api 7.1.1 Filesystem Modification Oct 6, 2026
node-gyp 13.1.0 Spawning processes and shell commands Oct 6, 2026
postcss 8.5.23 Path Traversal Risk in Source Map Loading Oct 6, 2026
next 16.3.8 Remote binary download without integrity verification Oct 6, 2026
next-themes 0.4.6 dynamic code execution Oct 6, 2026
next-intl 4.14.9 Dynamic code execution via SWC transform with native plugin Oct 6, 2026
next-auth 4.24.15 Prototype Pollution Oct 6, 2026
lucide-react 1.50.0 Malformed data structure Oct 6, 2026
napi-postinstall 0.3.4 Shell command execution with string interpolation Oct 6, 2026
mz 2.7.0 Sensitive module re-export Oct 6, 2026
minizlib 3.1.0 Private/internal Node.js API access Oct 6, 2026
marked 15.0.12 Dynamic code execution via config file loading Oct 6, 2026
meow 13.2.0 Potential data exfiltration via process.exit and console output Oct 6, 2026
make-asynchronous 1.0.1 Dynamic code execution Oct 6, 2026
lodash-es 4.18.1 Dynamic code execution Oct 6, 2026
lightningcss 1.32.0 Dynamic import with computed module name Oct 6, 2026
undici 8.11.2 Potential path traversal / unsafe filename handling Oct 6, 2026
json5 1.0.2 Module system modification Oct 6, 2026
jsdom 30.1.1 Dynamic code execution Oct 6, 2026
jose 4.15.9 Insecure JWT implementation (algorithm: none) Oct 6, 2026
jiti 2.7.0 Dynamic import with computed path Oct 6, 2026
java-properties 1.0.2 File system access Oct 6, 2026
husky 9.1.7 File system manipulation outside package scope Oct 6, 2026

About this list

What counts as a malicious npm package?

A package that does something its users did not ask for and would not agree to: running code at install time to steal tokens or environment variables, sending data to an attacker's server, opening a backdoor, mining cryptocurrency or swapping wallet addresses.

Are all packages on this list malware?

No. Critical findings describe dangerous or likely malicious behavior. High and medium findings flag risky patterns, such as dynamic code execution or disabled TLS checks, that are common in legitimate packages and need human review.

How are packages added to the tracker?

Every package scanned with Togoder Security, by anyone, is reviewed file by file by an AI model. Versions whose review produced critical, high or medium findings appear here automatically.

How do I check my own project for malicious packages?

Upload your package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock or another lockfile at https://security.togoder.click/scan. Parsing and the price quote are free, and files that were already reviewed cost nothing.