Summary
Togoder Security scanned the npm package @babel/generator@7.29.8 on Oct 6, 2026. An AI review of 21 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/buffer.js | safe | No malicious patterns detected; the code is a standard source map buffer utility with no network, filesystem, process, or dynamic code execution activity. |
| lib/generators/base.js | safe | No malicious patterns detected; the file is a standard AST code generator from Babel with no network, filesystem, process, or dynamic execution activity. |
| lib/generators/classes.js | safe | This is a standard Babel code generator module that only prints AST node representations of classes and contains no malicious patterns. |
| lib/generators/deprecated.js | safe | This is a code generator module from a parser/printer library that emits syntax tokens for deprecated AST node types; it contains no network, filesystem, process, or dynamic execution behavior. |
| lib/generators/expressions.js | safe | The file is a Babel AST expression code generator with no network, filesystem, process execution, or obfuscated malicious patterns. |
| lib/generators/flow.js | safe | This file contains only Babel AST generator code for Flow type syntax printing, with no network, filesystem, process, or dynamic execution behavior. |
| lib/generators/index.js | safe | No malicious patterns detected; the file only re-exports modules from local generator files. |
| lib/generators/jsx.js | safe | No malicious patterns detected |
| lib/generators/methods.js | safe | No malicious patterns detected; this is standard Babel code generator logic for printing function and method nodes. |
| lib/generators/modules.js | safe | No malicious patterns detected; this is a standard Babel code generator module for import/export AST nodes with no network, filesystem, process, or dynamic execution activity. |
| lib/generators/statements.js | safe | This file is a standard Babel code generator for JavaScript statements and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity. |
| lib/generators/template-literals.js | safe | No malicious patterns detected |
| lib/generators/types.js | safe | No malicious patterns detected; the file is a standard Babel code generator for AST node types with no network, filesystem, process, or obfuscated behavior. |
| lib/generators/typescript.js | safe | This is a standard TypeScript AST generator/printer module with no malicious patterns, network activity, file system access, or dynamic code execution. |
| lib/index.js | safe | This is a legitimate Babel code generator module that normalizes options and delegates to internal source-map and printer modules without any malicious patterns. |
| lib/node/index.js | safe | No malicious patterns detected; the code is a standard Babel parser utility for parenthesis and token context handling with no network, filesystem, or process activity. |
| lib/node/parentheses.js | safe | This is a standard Babel parentheses logic module with no malicious patterns, no I/O, no network access, and no dynamic code execution. |
| lib/nodes.js | safe | No malicious patterns detected |
| lib/printer.js | safe | This is a legitimate Babel code generator printer module with no malicious patterns detected. |
| lib/source-map.js | safe | No malicious patterns detected |
| lib/token-map.js | safe | No malicious patterns detected; the code is a legitimate Babel token mapping utility with no network, filesystem, process, or dynamic code execution behavior. |
Scanned versions of @babel/generator
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 7.29.8 | No issues | 21 | Oct 6, 2026 |
Frequently asked questions
Is @babel/generator safe to use?
Our AI source review of @babel/generator@7.29.8 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @babel/generator contain malware?
No malware was identified in @babel/generator@7.29.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @babel/generator checked?
Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @babel/generator together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @babel/generator@7.29.8, cost nothing.