Summary
Togoder Security scanned the npm package @asamuzakjp/dom-selector@9.2.1 on Oct 6, 2026. An AI review of 15 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic code execution
NPS-655C1DE89062
The compile method uses Function() constructor to generate executable selector-matching functions from string-built source. While this is the core design of nwsapi and mirrors the upstream library's behavior, using new Function with dynamically assembled strings is inherently risky because it relies on strict input sanitization (via #reValidator regex) to prevent code injection. If the selector validation regex is bypassed or flawed, arbitrary JavaScript could be injected into the generated function body. The selector strings are also used to build regexes and concatenated into source code in multiple places (compileId, compileClass, compileAttribute), increasing the attack surface.
Potential ReDoS in regex validation
NPS-A10E227D6BE4
The selector parser uses multiple complex regular expressions with nested quantifiers and backreferences (e.g., #reValidator, REX.splitGroup, REX.commaGroup, patterns for attributes/pseudos with (?:...)*? and {0,255} bounds). These are used against user-supplied selector strings. Although the library includes length bounds (e.g., {0,255}), such patterns have historically been vulnerable to catastrophic backtracking with crafted inputs, potentially causing denial of service.
DOM API usage / dynamic HTML query
NPS-689E6BA633F4
The :has() pseudo-class handling directly interpolates the parsed expression into e.querySelector(":scope ${escapedExpr}"). If the escaping (backslash and quote escaping) is insufficient against certain selector strings, this could lead to unexpected DOM query behavior. It does not execute code, but it is a dynamic string-to-DOM-query path worth noting.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/js/nwsapi.js | medium | The file is a fork of the nwsapi CSS selector engine that uses new Function to compile selectors and complex regex-based parsing, which are inherent risk factors but consistent with the upstream library's design; no exfiltration, credential harvesting, network calls, or process spawning were found. |
| src/index.js | safe | No malicious patterns detected; the code is a legitimate CSS selector engine with no exfiltration, obfuscation, or suspicious behavior. |
| src/js/constant.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/evaluator.js | safe | No malicious patterns detected; the code implements a standard CSS selector evaluator with no external network, filesystem, process, or dynamic code execution activity. |
| src/js/event.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/finder.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/mapper.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/matcher.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/parser.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/processor.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/pseudo-class.js | safe | No malicious patterns detected; the file is a legitimate CSS pseudo-class evaluator with no network, filesystem, process, or obfuscated code concerns. |
| src/js/selector.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/shadow.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/traverser.js | safe | Cleared by Jev triage; no further analysis needed |
| src/js/utility.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of @asamuzakjp/dom-selector
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 9.2.1 | Needs review | 15 | Oct 6, 2026 |
Frequently asked questions
Is @asamuzakjp/dom-selector safe to use?
No confirmed malware was found in @asamuzakjp/dom-selector@9.2.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @asamuzakjp/dom-selector contain malware?
No malware was identified in @asamuzakjp/dom-selector@9.2.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @asamuzakjp/dom-selector checked?
Togoder Security downloaded the published npm package and had an AI model read its 15 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @asamuzakjp/dom-selector together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @asamuzakjp/dom-selector@9.2.1, cost nothing.