Togoder security

npm package security report

@asamuzakjp/dom-selector@9.2.1 security report

Risky patterns found that deserve a look.

Needs review Version 9.2.1 Files reviewed 15 Size 257.3 KB Scanned

Summary

Togoder Security scanned the npm package @asamuzakjp/dom-selector@9.2.1 on Oct 6, 2026. An AI review of 15 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Dynamic code execution

NPS-655C1DE89062

The compile method uses Function() constructor to generate executable selector-matching functions from string-built source. While this is the core design of nwsapi and mirrors the upstream library's behavior, using new Function with dynamically assembled strings is inherently risky because it relies on strict input sanitization (via #reValidator regex) to prevent code injection. If the selector validation regex is bypassed or flawed, arbitrary JavaScript could be injected into the generated function body. The selector strings are also used to build regexes and concatenated into source code in multiple places (compileId, compileClass, compileAttribute), increasing the attack surface.

src/js/nwsapi.js
medium

Potential ReDoS in regex validation

NPS-A10E227D6BE4

The selector parser uses multiple complex regular expressions with nested quantifiers and backreferences (e.g., #reValidator, REX.splitGroup, REX.commaGroup, patterns for attributes/pseudos with (?:...)*? and {0,255} bounds). These are used against user-supplied selector strings. Although the library includes length bounds (e.g., {0,255}), such patterns have historically been vulnerable to catastrophic backtracking with crafted inputs, potentially causing denial of service.

src/js/nwsapi.js
low

DOM API usage / dynamic HTML query

NPS-689E6BA633F4

The :has() pseudo-class handling directly interpolates the parsed expression into e.querySelector(":scope ${escapedExpr}"). If the escaping (backslash and quote escaping) is insufficient against certain selector strings, this could lead to unexpected DOM query behavior. It does not execute code, but it is a dynamic string-to-DOM-query path worth noting.

src/js/nwsapi.js

Files reviewed

FileVerdictWhat the reviewer saw
src/js/nwsapi.js medium The file is a fork of the nwsapi CSS selector engine that uses new Function to compile selectors and complex regex-based parsing, which are inherent risk factors but consistent with the upstream library's design; no exfiltration, credential harvesting, network calls, or process spawning were found.
src/index.js safe No malicious patterns detected; the code is a legitimate CSS selector engine with no exfiltration, obfuscation, or suspicious behavior.
src/js/constant.js safe Cleared by Jev triage; no further analysis needed
src/js/evaluator.js safe No malicious patterns detected; the code implements a standard CSS selector evaluator with no external network, filesystem, process, or dynamic code execution activity.
src/js/event.js safe Cleared by Jev triage; no further analysis needed
src/js/finder.js safe Cleared by Jev triage; no further analysis needed
src/js/mapper.js safe Cleared by Jev triage; no further analysis needed
src/js/matcher.js safe Cleared by Jev triage; no further analysis needed
src/js/parser.js safe Cleared by Jev triage; no further analysis needed
src/js/processor.js safe Cleared by Jev triage; no further analysis needed
src/js/pseudo-class.js safe No malicious patterns detected; the file is a legitimate CSS pseudo-class evaluator with no network, filesystem, process, or obfuscated code concerns.
src/js/selector.js safe Cleared by Jev triage; no further analysis needed
src/js/shadow.js safe Cleared by Jev triage; no further analysis needed
src/js/traverser.js safe Cleared by Jev triage; no further analysis needed
src/js/utility.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is @asamuzakjp/dom-selector safe to use?

No confirmed malware was found in @asamuzakjp/dom-selector@9.2.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @asamuzakjp/dom-selector contain malware?

No malware was identified in @asamuzakjp/dom-selector@9.2.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @asamuzakjp/dom-selector checked?

Togoder Security downloaded the published npm package and had an AI model read its 15 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @asamuzakjp/dom-selector together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @asamuzakjp/dom-selector@9.2.1, cost nothing.

Related security reports