Summary
Togoder Security scanned the npm package @babel/helpers@7.29.7 on Oct 6, 2026. An AI review of 123 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
dynamic code execution
NPS-A0F4B763DEBC
Uses Function.toString.call(fn) to inspect a function's source. This is not code execution (no eval/new Function), but it does read the function's string representation, which is a common safe utility pattern used by Babel helpers.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/helpers/AwaitValue.js | safe | No malicious patterns detected |
| lib/helpers/OverloadYield.js | safe | No malicious patterns detected; the file is a trivial Babel helper constructor with no I/O, network, or dynamic execution. |
| lib/helpers/applyDecoratedDescriptor.js | safe | No malicious patterns detected; this is a standard Babel helper for applying decorated descriptors. |
| lib/helpers/applyDecs.js | safe | No malicious patterns detected; this is a legitimate Babel helper implementation for decorators. |
| lib/helpers/applyDecs2203.js | safe | This is a legitimate Babel helper for applying decorators (applyDecs2203) with no malicious patterns, network activity, process execution, or credential access. |
| lib/helpers/applyDecs2203R.js | safe | No malicious patterns detected; the file is a standard Babel decorators helper implementation with no network, filesystem, process, or dynamic execution behavior. |
| lib/helpers/applyDecs2301.js | safe | This is a legitimate Babel decorators transform helper (applyDecs2301) with no malicious patterns; it only implements decorator application logic using standard library calls and no network, filesystem, process, or eval operations. |
| lib/helpers/applyDecs2305.js | safe | This is a legitimate Babel runtime helper implementing JavaScript decorators, with no malicious patterns or security concerns. |
| lib/helpers/applyDecs2311.js | safe | No malicious patterns detected; file is a standard Babel decorator helper with no network, filesystem, process, or dynamic-execution activity. |
| lib/helpers/arrayLikeToArray.js | safe | No malicious patterns detected; the code is a standard array-like to array conversion helper with no network, filesystem, process, or dynamic execution behavior. |
| lib/helpers/arrayWithHoles.js | safe | No malicious patterns detected; the file is a simple Babel helper that checks if a value is an array. |
| lib/helpers/arrayWithoutHoles.js | safe | No malicious patterns detected; the file is a simple Babel helper function that safely converts array-like objects to arrays. |
| lib/helpers/assertClassBrand.js | safe | No malicious patterns detected |
| lib/helpers/assertThisInitialized.js | safe | No malicious patterns detected |
| lib/helpers/asyncGeneratorDelegate.js | safe | No malicious patterns detected; this is a standard Babel helper for async generator delegation with no network, filesystem, process, or dynamic execution activity. |
| lib/helpers/asyncIterator.js | safe | No malicious patterns detected; the code is a standard Babel helper for async iterator normalization. |
| lib/helpers/asyncToGenerator.js | safe | This is a standard Babel-generated asyncToGenerator helper with no malicious patterns, network access, file system operations, or dynamic code execution. |
| lib/helpers/awaitAsyncGenerator.js | safe | No malicious patterns detected |
| lib/helpers/callSuper.js | safe | This is benign Babel helper code for calling super constructors; no malicious patterns detected. |
| lib/helpers/checkInRHS.js | safe | No malicious patterns detected |
| lib/helpers/checkPrivateRedeclaration.js | safe | No malicious patterns detected |
| lib/helpers/classApplyDescriptorDestructureSet.js | safe | No malicious patterns detected; this is a benign Babel helper for applying private field descriptors in destructuring assignment. |
| lib/helpers/classApplyDescriptorGet.js | safe | No malicious patterns detected |
| lib/helpers/classApplyDescriptorSet.js | safe | This is a standard Babel helper function for applying property descriptors; no malicious patterns detected. |
| lib/helpers/classCallCheck.js | safe | No malicious patterns detected |
Show 98 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/helpers/classCheckPrivateStaticAccess.js | safe | No malicious patterns detected |
| lib/helpers/classCheckPrivateStaticFieldDescriptor.js | safe | No malicious patterns detected |
| lib/helpers/classExtractFieldDescriptor.js | safe | No malicious patterns detected |
| lib/helpers/classNameTDZError.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateFieldGet.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateFieldGet2.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateFieldInitSpec.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateFieldLooseBase.js | safe | No malicious patterns detected; the file is a standard Babel helper for private field access with no network, file system, process, or dynamic execution activity. |
| lib/helpers/classPrivateFieldLooseKey.js | safe | No malicious patterns detected; the file is a simple Babel helper that generates unique private field keys with no network, filesystem, or dynamic code execution behavior. |
| lib/helpers/classPrivateFieldSet.js | safe | No malicious patterns detected; this is a standard Babel helper for setting private class fields. |
| lib/helpers/classPrivateFieldSet2.js | safe | No malicious patterns detected; the file is a standard Babel helper for setting private class fields with no network, filesystem, process, or dynamic execution behavior. |
| lib/helpers/classPrivateGetter.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateMethodGet.js | safe | No malicious patterns detected |
| lib/helpers/classPrivateMethodInitSpec.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private method initialization with no network, filesystem, process, or dynamic code execution behavior. |
| lib/helpers/classPrivateMethodSet.js | safe | No malicious patterns detected; the file is a harmless Babel helper that throws a TypeError when attempting to reassign a private method. |
| lib/helpers/classPrivateSetter.js | safe | No malicious patterns detected |
| lib/helpers/classStaticPrivateFieldDestructureSet.js | safe | No malicious patterns detected; the code is a standard Babel helper for private static field destructuring with no network, filesystem, or process activity. |
| lib/helpers/classStaticPrivateFieldSpecGet.js | safe | No malicious patterns detected |
| lib/helpers/classStaticPrivateFieldSpecSet.js | safe | This is a standard Babel runtime helper for setting private static fields; no malicious patterns detected. |
| lib/helpers/classStaticPrivateMethodGet.js | safe | No malicious patterns detected; the file only contains a Babel-generated helper function for accessing static private methods with a simple brand assertion. |
| lib/helpers/classStaticPrivateMethodSet.js | safe | No malicious patterns detected |
| lib/helpers/construct.js | safe | This is a standard Babel helper for the _construct function, with no malicious patterns, network activity, obfuscation, or install-time behavior detected. |
| lib/helpers/createClass.js | safe | This is a standard Babel helper for creating ES6 classes with proto and static properties; no malicious patterns detected. |
| lib/helpers/createForOfIteratorHelper.js | safe | No malicious patterns detected; the code is a standard Babel helper for iterating over iterables and arrays. |
| lib/helpers/createForOfIteratorHelperLoose.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for loosely iterating over iterables. |
| lib/helpers/createSuper.js | safe | No malicious patterns detected |
| lib/helpers/decorate.js | safe | No malicious patterns detected; the file is a standard Babel/TypeScript decorator helper implementation with no network, filesystem, process, or dynamic code execution concerns. |
| lib/helpers/defaults.js | safe | No malicious patterns detected |
| lib/helpers/defineAccessor.js | safe | No malicious patterns detected |
| lib/helpers/defineEnumerableProperties.js | safe | This is a standard Babel helper that defines enumerable properties on objects; no malicious patterns, network activity, credential harvesting, or dynamic code execution are present. |
| lib/helpers/defineProperty.js | safe | No malicious patterns detected; the file is a standard Babel helper for defining object properties. |
| lib/helpers/dispose.js | safe | No malicious patterns detected |
| lib/helpers/extends.js | safe | This is a standard Babel transpiled Object.assign polyfill/helper with no malicious patterns, network activity, credential access, or dynamic code execution. |
| lib/helpers/get.js | safe | No malicious patterns detected; this is a standard Babel-transpiled helper for Reflect.get with a fallback implementation. |
| lib/helpers/getPrototypeOf.js | safe | No malicious patterns detected |
| lib/helpers/identity.js | safe | No malicious patterns detected |
| lib/helpers/importDeferProxy.js | safe | No malicious patterns detected; the code is a standard import defer proxy implementation with no network, filesystem, process, or credential access. |
| lib/helpers/inherits.js | safe | No malicious patterns detected; this is a standard Babel helper implementing prototype inheritance. |
| lib/helpers/inheritsLoose.js | safe | No malicious patterns detected |
| lib/helpers/initializerDefineProperty.js | safe | No malicious patterns detected |
| lib/helpers/initializerWarningHelper.js | safe | No malicious patterns detected; the file only throws a descriptive error for missing decorator transform configuration. |
| lib/helpers/instanceof.js | safe | No malicious patterns detected |
| lib/helpers/interopRequireDefault.js | safe | No malicious patterns detected |
| lib/helpers/interopRequireWildcard.js | safe | This is a standard Babel interop helper that safely wraps module objects using WeakMap caching and performs no malicious operations. |
| lib/helpers/isNativeFunction.js | safe | The helper only inspects a function's string representation to detect native functions and contains no malicious patterns, network activity, credential access, or code execution. |
| lib/helpers/isNativeReflectConstruct.js | safe | This is a benign Babel transpilation helper that detects native Reflect.construct support; no malicious patterns were found. |
| lib/helpers/iterableToArray.js | safe | No malicious patterns detected in the iterableToArray helper function, which only performs a safe iterable-to-array conversion. |
| lib/helpers/iterableToArrayLimit.js | safe | No malicious patterns detected |
| lib/helpers/jsx.js | safe | This is a standard Babel-compiled React JSX element creation helper with no network, filesystem, process, or dynamic code execution activity. |
| lib/helpers/maybeArrayLike.js | safe | This is a standard Babel helper that safely converts array-like values to arrays with no malicious patterns. |
| lib/helpers/newArrowCheck.js | safe | No malicious patterns detected |
| lib/helpers/nonIterableRest.js | safe | No malicious patterns detected; the file only provides a Babel helper that throws a TypeError for non-iterable destructuring. |
| lib/helpers/nonIterableSpread.js | safe | No malicious patterns detected |
| lib/helpers/nullishReceiverError.js | safe | No malicious patterns detected |
| lib/helpers/objectDestructuringEmpty.js | safe | No malicious patterns detected |
| lib/helpers/objectSpread.js | safe | No malicious patterns detected; this is a standard Babel-generated helper for object spread that only uses local module imports and object property operations. |
| lib/helpers/objectSpread2.js | safe | This is a standard Babel helper implementing Object spread semantics with no network, filesystem, process, or dynamic code execution patterns. |
| lib/helpers/objectWithoutProperties.js | safe | This is a standard Babel helper function for omitting properties from objects with no malicious patterns detected |
| lib/helpers/objectWithoutPropertiesLoose.js | safe | No malicious patterns detected |
| lib/helpers/possibleConstructorReturn.js | safe | This is a standard Babel runtime helper for enforcing derived constructor return semantics with no malicious patterns detected. |
| lib/helpers/readOnlyError.js | safe | No malicious patterns detected |
| lib/helpers/regenerator.js | safe | This is a standard Babel regenerator runtime helper with no malicious patterns, network activity, or credential access. |
| lib/helpers/regeneratorAsync.js | safe | No malicious patterns detected; the file is a standard Babel helper for async generator execution. |
| lib/helpers/regeneratorAsyncGen.js | safe | No malicious patterns detected; this is a standard Babel/regenerator runtime helper for async generators with no network, filesystem, process, or dynamic execution behavior. |
| lib/helpers/regeneratorAsyncIterator.js | safe | No malicious patterns detected; the code implements a standard async iterator helper for regenerator runtime without any suspicious behavior. |
| lib/helpers/regeneratorDefine.js | safe | No malicious patterns detected; this is a benign Babel regenerator helper defining iterator methods and polyfilling Object.defineProperty behavior. |
| lib/helpers/regeneratorKeys.js | safe | No malicious patterns detected; the file is a standard regenerator runtime helper for iterating object keys with no network, filesystem, process, or dynamic code execution activity. |
| lib/helpers/regeneratorRuntime.js | safe | No malicious patterns detected; this is a legitimate Babel helper implementing the regenerator runtime for async/generator functions with no network, filesystem, process, or obfuscation concerns. |
| lib/helpers/regeneratorValues.js | safe | No malicious patterns detected; the file only implements a standard iterable-to-iterator helper without network, filesystem, process, or dynamic code execution. |
| lib/helpers/set.js | safe | No malicious patterns detected; the code is a standard Babel helper for property assignment with prototype chain fallbacks. |
| lib/helpers/setFunctionName.js | safe | No malicious patterns detected |
| lib/helpers/setPrototypeOf.js | safe | No malicious patterns detected; the file is a standard Babel transpiled helper for setting an object's prototype. |
| lib/helpers/skipFirstGeneratorNext.js | safe | No malicious patterns detected; the file contains a benign helper for skipping the first yield of a generator function. |
| lib/helpers/slicedToArray.js | safe | No malicious patterns detected; this is a standard Babel helper for destructuring arrays into slices. |
| lib/helpers/superPropBase.js | safe | No malicious patterns detected; this is a standard Babel helper for resolving superclass property access. |
| lib/helpers/superPropGet.js | safe | This is a standard Babel helper for accessing super class properties; no malicious patterns detected. |
| lib/helpers/superPropSet.js | safe | No malicious patterns detected |
| lib/helpers/taggedTemplateLiteral.js | safe | No malicious patterns detected |
| lib/helpers/taggedTemplateLiteralLoose.js | safe | No malicious patterns detected |
| lib/helpers/tdz.js | safe | No malicious patterns detected |
| lib/helpers/temporalRef.js | safe | No malicious patterns detected; this is a standard Babel helper for temporal dead zone reference checking. |
| lib/helpers/temporalUndefined.js | safe | No malicious patterns detected |
| lib/helpers/toArray.js | safe | This is a standard Babel transpiled helper function for converting values to arrays, with no malicious patterns detected. |
| lib/helpers/toConsumableArray.js | safe | No malicious patterns detected |
| lib/helpers/toPrimitive.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing the ECMAScript ToPrimitive abstract operation. |
| lib/helpers/toPropertyKey.js | safe | No malicious patterns detected; the code is a straightforward Babel-compiled utility for converting values to property keys. |
| lib/helpers/toSetter.js | safe | No malicious patterns detected; the file contains a small utility function that creates an object with a setter invoking a provided callback. |
| lib/helpers/tsRewriteRelativeImportExtensions.js | safe | No malicious patterns detected |
| lib/helpers/typeof.js | safe | No malicious patterns detected; this is a standard Babel-generated _typeof helper function with no external I/O, dynamic code execution, or suspicious behavior. |
| lib/helpers/unsupportedIterableToArray.js | safe | The file is a standard Babel helper for converting iterable-like objects to arrays, with no malicious patterns detected. |
| lib/helpers/using.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing the using declaration disposal logic without any network, filesystem, process, or dynamic execution behavior. |
| lib/helpers/usingCtx.js | safe | This is a standard Babel-transpiled helper implementing the TC39 'using' / 'await using' (explicit resource management) proposal; it contains no malicious patterns such as network access, credential harvesting, obfuscation, or process spawning. |
| lib/helpers/wrapAsyncGenerator.js | safe | This is a standard Babel runtime helper for wrapping async generators with no network, filesystem, process, or obfuscated code patterns. |
| lib/helpers/wrapNativeSuper.js | safe | No malicious patterns detected; the code is a standard Babel helper for wrapping native super classes without any network, filesystem, shell, or dynamic execution activity. |
| lib/helpers/wrapRegExp.js | safe | No malicious patterns detected; the code is a legitimate Babel helper for wrapping RegExp with named capture group support. |
| lib/helpers/writeOnlyError.js | safe | No malicious patterns detected |
| lib/index.js | safe | No malicious patterns detected |
Frequently asked questions
Is @babel/helpers safe to use?
Our AI source review of @babel/helpers@7.29.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @babel/helpers contain malware?
No malware was identified in @babel/helpers@7.29.7 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @babel/helpers checked?
Togoder Security downloaded the published npm package and had an AI model read its 123 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @babel/helpers together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @babel/helpers@7.29.7, cost nothing.