Key takeaways
- Togoder Security reads the published source of every package version; it does not rely on advisory databases.
- Packages are downloaded from the official registries and never executed during a scan.
- Verdicts are cached per file by SHA-256 hash, so identical code is reviewed once and reused across packages and versions.
- Findings are AI judgments with file and line references; critical findings should be confirmed by a human.
1. Resolve the dependency tree
Lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock, go.sum, Gemfile.lock, composer.lock) already pin exact versions, so we scan exactly what your installer would install. Manifests and single package names are resolved to the versions the registry would serve today, including transitive dependencies.
2. Download from the official registry
Each version is fetched from npm, PyPI, crates.io, the Go module proxy, RubyGems or Packagist and unpacked into an isolated directory. Nothing is installed and no lifecycle script, setup.py, build.rs or init() runs. Every file is hashed with SHA-256.
3. Triage
Binary files, images, lockfiles and other non-code assets are skipped. A fast triage model screens each remaining source file; files it is confident are ordinary library code are cleared. The rest go to full review. Install-time entry points (npm lifecycle scripts, setup.py, .pth files, build.rs) are always reviewed in full.
4. AI source review
A large language model reads each file and reports concrete findings with severity, file, line, a description of what the code does and a recommendation. It looks for:
- Install-time payloads: npm preinstall/postinstall scripts, setup.py and .pth files, build.rs, Go init() and code that runs on import.
- Credential theft: reads of environment variables, SSH keys, .npmrc and cloud credentials, browser profiles and wallets.
- Exfiltration: network requests that send local data to external servers, DNS tunnelling, webhooks.
- Obfuscation: encoded blobs, eval of decoded strings, code downloaded and executed at runtime.
- Backdoors: reverse shells, spawned processes, file writes outside the package directory.
- Wallet drainers and miners: seed-phrase theft, clipboard address swapping, hidden mining.
- Risky patterns: disabled TLS verification, prototype pollution, unsafe dynamic code. Reported at lower severity.
5. Severity levels
| Level | Meaning |
|---|---|
| critical | Dangerous or likely malicious behavior. Do not install without review. |
| high | Risky behavior that could be abused or indicates poor security; review before use. |
| medium | Patterns that are risky in some contexts but common in legitimate code. |
| low | Informational notes. |
| safe | Nothing malicious or risky identified. |
6. Caching and public reports
Verdicts are stored per file hash and per package version. Every completed scan becomes a public report at a stable URL such as /npm/express, so the next person to check the same package gets the answer instantly and for free. Reports never show who requested a scan.
7. Limits
AI review is strong at reading what code does, but it is not a guarantee. Payloads that are only downloaded at runtime, logic split across many files, and very large or minified bundles are harder to judge, and the model can report false positives. Use findings as a prioritized list for human review, and combine source review with advisory scanners such as npm audit. See npm audit vs source-code scanning.
Frequently asked questions
Does the scanner run package code?
No. Packages are downloaded and unpacked, never installed or executed. The model only reads the source text, so install scripts cannot run during a scan.
Can AI review miss malware?
Yes. Heavily obfuscated payloads, code fetched at runtime from a server that behaves differently for scanners, and very large files are harder to judge. Treat a clean result as strong evidence, not proof.
Why are some files marked as cleared by triage?
A fast triage model first screens every file. Files it is confident are ordinary library code skip the full review. Everything else is read by the full model.
Why do repeated scans cost less?
Each file's verdict is stored by the SHA-256 hash of its exact contents. If any user has scanned the same bytes before, in any package or version, the cached verdict is reused for free.