# @babel/core@7.29.7 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:10:42.000Z
- Files reviewed: 65
- Findings: 3 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/@babel/core
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @babel/core@7.29.7 on Oct 6, 2026. An AI review of 65 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution / module loading with computed input

Finding ID: `NPS-E6298D5F840B`

File: `lib/config/files/configuration.js`

readConfigCode dynamically requires/imports configuration files based on file paths that can be discovered from the filesystem or resolved from user-supplied names. This is inherent to Babel's config loading design, but it means arbitrary JavaScript or TypeScript files (babel.config.js, .babelrc.js, etc.) in ancestor directories are executed during normal operation. In a malicious package context, this mechanism could be abused to execute attacker-controlled code if an attacker can place or influence config filenames.

### [medium] dynamic_module_loading

Finding ID: `NPS-93D2E83DD496`

File: `lib/config/files/module-types.js`

This code dynamically requires and loads arbitrary configuration files specified by the user (filepath), including CJS, ESM, and TypeScript files. This is expected behavior for Babel's config loading system, but it means any path passed by a user or attacker-controlled input could result in executing arbitrary local code. The loadMjsFromPath function dynamically imports user-specified paths via import(url).

### [medium] runtime_code_compilation

Finding ID: `NPS-C20AC0BB4DA2`

File: `lib/config/files/module-types.js`

ensureTsSupport installs a hook into require.extensions[ext] that compiles and executes TypeScript config files at runtime using transformFileSync and m._compile. This is dynamic code execution of user-supplied config files, though it is a documented Babel feature and not obfuscated.

### [low] Environment variable access

Finding ID: `NPS-94A4B2AF1F58`

File: `lib/config/files/configuration.js`

resolveShowConfigPath reads process.env.BABEL_SHOW_CONFIG_FOR and resolves it to an absolute path, then stats the file. This is a legitimate Babel debugging feature, but environment-variable-driven path resolution can be a vector for path manipulation if combined with untrusted environment control.

### [low] Dynamic require.resolve fallback

Finding ID: `NPS-38A4DBCC6F50`

File: `lib/config/files/configuration.js`

loadConfig uses a custom fallback implementation invoking require('module')._findPath and _nodeModulePaths to resolve module names against a caller-supplied directory. While standard for Babel config loading, dynamic module resolution with computed input is a pattern that can be abused to load arbitrary modules if the 'name' argument is attacker-controlled.

### [low] Dynamic import with external input

Finding ID: `NPS-58B951D6CB2B`

File: `lib/config/files/import.cjs:2`

The function accepts a filepath parameter and passes it directly to import(), enabling dynamic module loading based on arbitrary input. If this filepath is controllable by an attacker or external data, it could allow loading of malicious modules. However, no obfuscation, exfiltration, or other malicious behavior is present.

### [low] call_stack_manipulation

Finding ID: `NPS-380B2A07F7E8`

File: `lib/config/files/module-types.js`

Uses endHiddenCallStack (rewrite-stack-trace) to obfuscate require and import call origins when loading config files. This can hide the origin of execution in stack traces, which is a minor security-relevant pattern, though commonly used by Babel for cleaner error output.

### [low] dynamic module resolution and loading

Finding ID: `NPS-E40D4C3B14CD`

File: `lib/config/files/plugins.js:55`

The code resolves and requires/imports modules based on plugin/preset names supplied by the user through Babel configuration. While this is dynamic module loading, it is the intended core functionality of Babel's plugin/preset system and does not use computed external input beyond expected user configuration.

### [low] use of require.resolve with internal Node.js APIs

Finding ID: `NPS-AB3401E780EE`

File: `lib/config/files/plugins.js:109`

For older Node versions, the code uses the undocumented module._findPath and module._nodeModulePaths APIs to resolve modules. This is a compatibility workaround, not malicious, but relies on internal APIs.

### [low] External source map file loading

Finding ID: `NPS-7ADF4C6A9F63`

File: `lib/transformation/normalize-file.js`

The code reads and parses external source map files referenced by sourceMappingURL comments in input code. While this is standard Babel functionality, it can load arbitrary files from the filesystem relative to the input filename/root if an attacker controls the source code being processed. This is not malicious per se, but represents a potential file disclosure vector in untrusted code scenarios.

### [low] Dynamic module loading

Finding ID: `NPS-AD60FA9DEAA6`

File: `lib/transformation/normalize-file.js`

Multiple require() calls are used within lazy-loading wrapper functions (debug, @babel/types, convert-source-map). This pattern is standard for reducing startup cost and not inherently malicious, but dynamic module loading is a common technique in supply-chain attacks.

## Files reviewed

- `lib/config/files/configuration.js` (medium): This is the legitimate Babel core configuration loader; it dynamically executes config files and resolves modules by design, with no evidence of data exfiltration, credential harvesting, obfuscation, network calls, shell spawning, or backdoors.
- `lib/config/files/import.cjs` (medium): The file only wraps dynamic import() with a caller-supplied path; no malicious patterns detected, but dynamic import from external input is a minor concern.
- `lib/config/files/module-types.js` (medium): This is standard Babel config-loading code that dynamically loads and compiles user-provided config files (including TS via require.extensions hooks), which is expected behavior for the package but involves dynamic code execution of local user files.
- `lib/transformation/normalize-file.js` (medium): This appears to be legitimate Babel transformation code with no clear malicious patterns; the only notable behavior is reading external source map files referenced in input code.
- `lib/config/cache-contexts.js` (safe): No malicious patterns detected
- `lib/config/caching.js` (safe): No malicious patterns detected
- `lib/config/config-chain.js` (safe): No malicious patterns detected
- `lib/config/config-descriptors.js` (safe): No malicious patterns detected in the Babel configuration descriptor module; it contains standard plugin/preset resolution, caching, and validation logic.
- `lib/config/files/index-browser.js` (safe): No malicious patterns detected; this is a harmless browser stub for Babel config loading that intentionally no-ops or throws clear errors.
- `lib/config/files/index.js` (safe): No malicious patterns detected
- `lib/config/files/package.js` (safe): No malicious patterns detected; the code safely reads and validates package.json files while walking up the directory tree.
- `lib/config/files/plugins.js` (safe): This is a legitimate Babel configuration module for loading plugins and presets; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors were detected.
- `lib/config/files/types.js` (safe): No malicious patterns detected; the file contains only a source map reference and a no-op expression.
- `lib/config/files/utils.js` (safe): No malicious patterns detected; the code is a standard file caching utility from Babel with no exfiltration, obfuscation, or suspicious behavior.
- `lib/config/full.js` (safe): No malicious patterns detected
- `lib/config/helpers/config-api.js` (safe): This is a standard Babel configuration API helper file with no malicious patterns, network calls, or suspicious behavior detected.
- `lib/config/helpers/deep-array.js` (safe): No malicious patterns detected
- `lib/config/helpers/environment.js` (safe): No malicious patterns detected; the code only reads standard BABEL_ENV/NODE_ENV environment variables with a default fallback.
- `lib/config/index.js` (safe): No malicious patterns detected
- `lib/config/item.js` (safe): No malicious patterns detected; this is a standard Babel configuration utility module with no network, filesystem, process, or obfuscated code.
- `lib/config/partial.js` (safe): This appears to be a legitimate Babel configuration loading module with no malicious patterns detected.
- `lib/config/pattern-to-regex.js` (safe): No malicious patterns detected
- `lib/config/plugin.js` (safe): No malicious patterns detected; this is a straightforward Babel plugin wrapper class with no network, filesystem, process, or dynamic code execution activity.
- `lib/config/printer.js` (safe): No malicious patterns detected; the code is a benign configuration printer for Babel that uses gensync for generator-based control flow without any network, filesystem, process, or dynamic execution risks.
- `lib/config/resolve-targets-browser.js` (safe): No malicious patterns detected; the file is a standard Babel browser-side helper that resolves compilation targets and does not perform any suspicious activity.
- `lib/config/resolve-targets.js` (safe): No malicious patterns detected; the file contains standard Babel target resolution logic using path and @babel/helper-compilation-targets with no exfiltration, obfuscation, or unsafe execution.
- `lib/config/util.js` (safe): No malicious patterns detected
- `lib/config/validation/option-assertions.js` (safe): No malicious patterns detected
- `lib/config/validation/options.js` (safe): No malicious patterns detected
- `lib/config/validation/plugins.js` (safe): No malicious patterns detected; the code performs static validation of Babel plugin configuration objects without any network, filesystem, process, or dynamic execution behavior.
- `lib/config/validation/removed.js` (safe): The file contains only static configuration metadata describing removed Babel options with human-readable deprecation messages and no executable, network, filesystem, or obfuscated behavior.
- `lib/errors/config-error.js` (safe): No malicious patterns detected
- `lib/errors/rewrite-stack-trace.js` (safe): No malicious patterns detected; the file only implements legitimate stack-trace manipulation utilities without network, filesystem, or code execution behavior.
- `lib/gensync-utils/async.js` (safe): This file contains standard async utility functions from the Babel/gensync ecosystem and exhibits no malicious patterns or security concerns.
- `lib/gensync-utils/fs.js` (safe): The file only wraps Node.js fs readFile/stat in gensync helpers with no suspicious behavior, exfiltration, or dynamic code execution.
- `lib/gensync-utils/functional.js` (safe): No malicious patterns detected; the code is a utility for memoizing generator functions with async support and does not exfiltrate data, execute dynamic code, or perform any suspicious activities.
- `lib/index.js` (safe): This is a standard Babel package entry point (lib/index.js) that re-exports public API functions with lazy getters; no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or backdoors were detected.
- `lib/parse.js` (safe): No malicious patterns detected; the file is a standard Babel parser wrapper with no exfiltration, obfuscation, or suspicious behavior.
- `lib/parser/index.js` (safe): No malicious patterns detected; the code is a legitimate Babel parser wrapper with no suspicious behavior.
- `lib/parser/util/missing-plugin-helper.js` (safe): This is a benign Babel utility that maps plugin names to documentation URLs for generating helpful error messages when experimental syntax plugins are missing.
- `lib/tools/build-external-helpers.js` (safe): No malicious patterns detected; this is a legitimate Babel build tool for generating external helpers.
- `lib/transform-ast.js` (safe): No malicious patterns detected; the code is a standard Babel AST transformation utility with no suspicious behavior.
- `lib/transform-file-browser.js` (safe): No malicious patterns detected; the file only contains browser stubs that reject file transformation operations.
- `lib/transform-file.js` (safe): No malicious patterns detected; the code is a standard Babel transformFile utility with no exfiltration, credential access, obfuscation, or dynamic code execution.
- `lib/transform.js` (safe): No malicious patterns detected; this is a standard Babel transform module with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `lib/transformation/block-hoist-plugin.js` (safe): No malicious patterns detected; the code implements a Babel plugin for block hoisting without any exfiltration, credential harvesting, obfuscation, or suspicious behaviors.
- `lib/transformation/file/babel-7-helpers.cjs` (safe): No malicious patterns detected
- `lib/transformation/file/file.js` (safe): No malicious patterns detected; this is legitimate Babel transformation file handling code from @babel/core.
- `lib/transformation/file/generate.js` (safe): No malicious patterns detected; the code is a standard Babel code generation module that uses only expected dependencies and performs no suspicious activities.
- `lib/transformation/file/merge-map.js` (safe): Source map merging utility with no malicious patterns; it only uses @jridgewell/remapping for legitimate source map composition and performs no network, filesystem, process, or dynamic code execution activity.
- `lib/transformation/index.js` (safe): No malicious patterns detected; the code is a standard Babel transformation module with no exfiltration, obfuscation, or suspicious behavior.
- `lib/transformation/normalize-opts.js` (safe): No malicious patterns detected; the code is a standard Babel option normalization utility that only uses path utilities and executes plugin callbacks from the provided configuration.
- `lib/transformation/plugin-pass.js` (safe): No malicious patterns detected; this is a benign Babel PluginPass class with no network, filesystem, process, or dynamic execution behavior.
- `lib/transformation/read-input-source-map-file-browser.js` (safe): No malicious patterns detected; the file is a simple browser stub that throws an error when reading input source maps.
- `lib/transformation/read-input-source-map-file.js` (safe): The file implements source map reading with path traversal protection and no suspicious or malicious patterns detected.
- `lib/transformation/util/clone-deep.js` (safe): This is a standard deep-clone utility for Babel AST nodes with cycle detection and a fallback to structuredClone; no malicious patterns were detected.
- `lib/vendor/import-meta-resolve.js` (safe): This is a legitimate Node.js module resolution ponyfill implementation with standard filesystem reads for package.json files, no network exfiltration, no obfuscation, no dynamic code execution, and no suspicious lifecycle behavior.
- `src/config/files/index-browser.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/config/files/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/config/resolve-targets-browser.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/config/resolve-targets.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/transform-file-browser.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/transform-file.ts` (safe): No malicious patterns detected; the file is a legitimate Babel transform-file helper using gensync and internal config/fs utilities.
- `src/transformation/read-input-source-map-file-browser.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/transformation/read-input-source-map-file.ts` (safe): No malicious patterns detected; the code performs only local source map file resolution and reading within package boundaries.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
