Summary
Togoder Security scanned the npm package @babel/runtime@7.28.6 on Oct 6, 2026. An AI review of 245 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
global namespace pollution
NPS-807A3722A0D7
Attempts to assign regeneratorRuntime to the global scope and explicitly sets globalThis.regeneratorRuntime. This pollutes the global environment but is the documented behavior of the Babel regenerator runtime compatibility shim.
dynamic code execution
NPS-9EFB544298AB
Uses Function('r', 'regeneratorRuntime = r')(runtime) as a fallback to intentionally assign a global variable in strict-mode environments where implicit global assignment fails. This is not obfuscated or input-driven, but Function() construction is a dynamic code execution primitive and can be flagged by security scanners.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| regenerator/index.js | medium | This is a standard Babel regenerator runtime compatibility shim; it only uses Function() for a deliberate global assignment fallback and shows no signs of exfiltration, credential theft, backdoors, or other malicious behavior. |
| helpers/AwaitValue.js | safe | No malicious patterns detected |
| helpers/OverloadYield.js | safe | No malicious patterns detected |
| helpers/applyDecoratedDescriptor.js | safe | No malicious patterns detected |
| helpers/applyDecs.js | safe | No malicious patterns detected in this Babel decorators helper, which contains only legitimate decorator transformation logic without network, file system, process, or credential access. |
| helpers/applyDecs2203.js | safe | No malicious patterns detected; this is a standard Babel decorator-runtime helper implementing ES decorators with no network, filesystem, process, or dynamic-evaluation behavior. |
| helpers/applyDecs2203R.js | safe | Legitimate Babel decorators helper implementation with no malicious patterns detected. |
| helpers/applyDecs2301.js | safe | No malicious patterns detected; the file is a standard Babel decorators helper implementing ES decorator semantics. |
| helpers/applyDecs2305.js | safe | No malicious patterns detected; this is a standard Babel helper for decorator semantics with no network, filesystem, process, or obfuscated code. |
| helpers/applyDecs2311.js | safe | This is a Babel helper for decorator metadata (applyDecs2311) with no malicious patterns, network calls, environment access, or dynamic code execution. |
| helpers/arrayLikeToArray.js | safe | This is a benign Babel helper function that converts array-like objects to arrays with no malicious patterns detected. |
| helpers/arrayWithHoles.js | safe | No malicious patterns detected |
| helpers/arrayWithoutHoles.js | safe | No malicious patterns detected |
| helpers/assertClassBrand.js | safe | No malicious patterns detected |
| helpers/assertThisInitialized.js | safe | No malicious patterns detected; the file is a standard Babel helper that validates this initialization. |
| helpers/asyncGeneratorDelegate.js | safe | No malicious patterns detected; this is a standard Babel helper for async generator delegation. |
| helpers/asyncIterator.js | safe | No malicious patterns detected; this is a standard Babel helper for async iteration with no network, filesystem, process, or dynamic code execution activity. |
| helpers/asyncToGenerator.js | safe | No malicious patterns detected; this is the standard Babel asyncToGenerator helper for converting async functions to generator-based promise chains. |
| helpers/awaitAsyncGenerator.js | safe | No malicious patterns detected; the file is a simple Babel helper that wraps a value in an OverloadYield object without any dangerous operations. |
| helpers/callSuper.js | safe | This is a standard Babel helper function for calling super constructors, with no malicious patterns detected. |
| helpers/checkInRHS.js | safe | No malicious patterns detected |
| helpers/checkPrivateRedeclaration.js | safe | No malicious patterns detected; the code is a standard Babel helper for private field redeclaration checks with no network, filesystem, process, or dynamic execution behavior. |
| helpers/classApplyDescriptorDestructureSet.js | safe | No malicious patterns detected; the file is a standard Babel helper for private field destructuring assignment. |
| helpers/classApplyDescriptorGet.js | safe | No malicious patterns detected |
| helpers/classApplyDescriptorSet.js | safe | No malicious patterns detected; the code is a standard Babel helper for setting private class fields with proper validation and no external interactions. |
Show 220 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| helpers/classCallCheck.js | safe | No malicious patterns detected |
| helpers/classCheckPrivateStaticAccess.js | safe | No malicious patterns detected |
| helpers/classCheckPrivateStaticFieldDescriptor.js | safe | No malicious patterns detected; the file is a benign Babel helper function for checking private static field declarations. |
| helpers/classExtractFieldDescriptor.js | safe | No malicious patterns detected; the file is a simple Babel helper that delegates to another local module. |
| helpers/classNameTDZError.js | safe | No malicious patterns detected |
| helpers/classPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| helpers/classPrivateFieldGet.js | safe | No malicious patterns detected; this is a standard Babel helper for accessing private class fields. |
| helpers/classPrivateFieldGet2.js | safe | No malicious patterns detected; this is a standard Babel helper for private field access with no external, network, filesystem, or process activity. |
| helpers/classPrivateFieldInitSpec.js | safe | This is a standard Babel helper for private field initialization with no malicious patterns detected. |
| helpers/classPrivateFieldLooseBase.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private field access checks. |
| helpers/classPrivateFieldLooseKey.js | safe | No malicious patterns detected in this small utility module that generates unique private field key names. |
| helpers/classPrivateFieldSet.js | safe | No malicious patterns detected; this is a standard Babel helper for setting private class fields. |
| helpers/classPrivateFieldSet2.js | safe | No malicious patterns detected; the helper performs a standard private field set using class brand assertion without any external calls, dynamic execution, or I/O. |
| helpers/classPrivateGetter.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private getter access. |
| helpers/classPrivateMethodGet.js | safe | No malicious patterns detected; this is a standard Babel helper for private method access. |
| helpers/classPrivateMethodInitSpec.js | safe | No malicious patterns detected |
| helpers/classPrivateMethodSet.js | safe | The file contains a standard Babel helper that throws a TypeError when attempting to reassign a private method; no malicious patterns detected. |
| helpers/classPrivateSetter.js | safe | No malicious patterns detected |
| helpers/classStaticPrivateFieldDestructureSet.js | safe | No malicious patterns detected; this is a standard Babel helper for private static field destructuring assignment. |
| helpers/classStaticPrivateFieldSpecGet.js | safe | No malicious patterns detected; this is a standard Babel helper for private static field access with no network, filesystem, process, or dynamic code execution behavior. |
| helpers/classStaticPrivateFieldSpecSet.js | safe | No malicious patterns detected |
| helpers/classStaticPrivateMethodGet.js | safe | No malicious patterns detected; the file is a standard Babel helper for accessing static private methods. |
| helpers/classStaticPrivateMethodSet.js | safe | No malicious patterns detected in this Babel runtime helper that only throws a TypeError for read-only static private field assignments. |
| helpers/construct.js | safe | No malicious patterns detected; this is a standard Babel helper for Reflect.construct fallback. |
| helpers/createClass.js | safe | No malicious patterns detected; the code is a standard Babel helper for defining class properties. |
| helpers/createForOfIteratorHelper.js | safe | No malicious patterns detected; this is a standard Babel transpilation helper for for-of iteration. |
| helpers/createForOfIteratorHelperLoose.js | safe | No malicious patterns detected; the file is a standard Babel helper for loose for-of iteration with no network, filesystem, process, or dynamic code execution behavior. |
| helpers/createSuper.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for creating superclass constructors. |
| helpers/decorate.js | safe | This is a standard Babel helper for JavaScript decorator transforms with no malicious patterns, network calls, credential access, or dynamic code execution. |
| helpers/defaults.js | safe | No malicious patterns detected; the code is a standard utility for copying default properties, with no network, filesystem, or process activity. |
| helpers/defineAccessor.js | safe | No malicious patterns detected; the code is a standard Babel helper for defining object properties. |
| helpers/defineEnumerableProperties.js | safe | This is a standard Babel helper function that defines enumerable properties; it contains no malicious patterns, network activity, credential access, dynamic code execution, or lifecycle scripts. |
| helpers/defineProperty.js | safe | No malicious patterns detected |
| helpers/dispose.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing the explicit resource management dispose protocol with SuppressedError support, containing no network, filesystem, process, or dynamic execution behavior. |
| helpers/esm/AwaitValue.js | safe | No malicious patterns detected |
| helpers/esm/OverloadYield.js | safe | No malicious patterns detected; the file defines a simple constructor function and exports it as default. |
| helpers/esm/applyDecoratedDescriptor.js | safe | No malicious patterns detected |
| helpers/esm/applyDecs.js | safe | No malicious patterns detected; the code is a standard Babel helper for implementing decorators and metadata, with no network, filesystem, process execution, or obfuscated behavior. |
| helpers/esm/applyDecs2203.js | safe | This is a standard Babel helper module implementing the decorators proposal (applyDecs2203) with no network, filesystem, process, or dynamic code execution patterns. |
| helpers/esm/applyDecs2203R.js | safe | This is a legitimate Babel helper for decorator transpilation with no malicious patterns detected. |
| helpers/esm/applyDecs2301.js | safe | No malicious patterns detected |
| helpers/esm/applyDecs2305.js | safe | This is a legitimate Babel helper implementing the ES decorators proposal (applyDecs2305) with no malicious patterns, network access, file system manipulation, or obfuscated code. |
| helpers/esm/applyDecs2311.js | safe | No malicious patterns detected |
| helpers/esm/arrayLikeToArray.js | safe | No malicious patterns detected |
| helpers/esm/arrayWithHoles.js | safe | No malicious patterns detected |
| helpers/esm/arrayWithoutHoles.js | safe | No malicious patterns detected |
| helpers/esm/assertClassBrand.js | safe | No malicious patterns detected |
| helpers/esm/assertThisInitialized.js | safe | No malicious patterns detected |
| helpers/esm/asyncGeneratorDelegate.js | safe | No malicious patterns detected; this is a standard Babel helper for async generator delegation. |
| helpers/esm/asyncIterator.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for async iterator support with no network, filesystem, or code execution behavior. |
| helpers/esm/asyncToGenerator.js | safe | No malicious patterns detected; the code is a standard Babel async-to-generator helper with no network, filesystem, process, or obfuscation activity. |
| helpers/esm/awaitAsyncGenerator.js | safe | The file is a trivial Babel helper that wraps a value in an OverloadYield object with no malicious behavior or side effects. |
| helpers/esm/callSuper.js | safe | No malicious patterns detected; this is a standard Babel transpilation helper for calling super constructors with no external network, filesystem, or code execution activity. |
| helpers/esm/checkInRHS.js | safe | No malicious patterns detected; the file is a standard Babel helper function for validating the right-hand side of 'in' operators. |
| helpers/esm/checkPrivateRedeclaration.js | safe | No malicious patterns detected |
| helpers/esm/classApplyDescriptorDestructureSet.js | safe | No malicious patterns detected |
| helpers/esm/classApplyDescriptorGet.js | safe | No malicious patterns detected; the code only provides a simple helper for accessing class descriptor values via getters or direct values. |
| helpers/esm/classApplyDescriptorSet.js | safe | This is a standard Babel helper function for applying values to class private fields with no malicious patterns detected. |
| helpers/esm/classCallCheck.js | safe | No malicious patterns detected |
| helpers/esm/classCheckPrivateStaticAccess.js | safe | Cleared by Jev triage; no further analysis needed |
| helpers/esm/classCheckPrivateStaticFieldDescriptor.js | safe | No malicious patterns detected; the code is a simple helper function that throws a TypeError when a private static field is accessed before its declaration. |
| helpers/esm/classExtractFieldDescriptor.js | safe | No malicious patterns detected |
| helpers/esm/classNameTDZError.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateFieldGet.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private class field access with no suspicious behavior. |
| helpers/esm/classPrivateFieldGet2.js | safe | No malicious patterns detected; the code is a legitimate Babel helper for private field access with no suspicious behavior. |
| helpers/esm/classPrivateFieldInitSpec.js | safe | This is a standard Babel helper for initializing private class fields; it performs no network, filesystem, or process operations and contains no malicious patterns. |
| helpers/esm/classPrivateFieldLooseBase.js | safe | This is a standard Babel helper function for private field access with no malicious patterns. |
| helpers/esm/classPrivateFieldLooseKey.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateFieldSet.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateFieldSet2.js | safe | This is a standard Babel transpilation helper for setting private class fields, with no malicious patterns or security concerns. |
| helpers/esm/classPrivateGetter.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateMethodGet.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateMethodInitSpec.js | safe | No malicious patterns detected |
| helpers/esm/classPrivateMethodSet.js | safe | Cleared by Jev triage; no further analysis needed |
| helpers/esm/classPrivateSetter.js | safe | No malicious patterns detected |
| helpers/esm/classStaticPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| helpers/esm/classStaticPrivateFieldSpecGet.js | safe | No malicious patterns detected; this is a standard Babel helper for accessing private static fields. |
| helpers/esm/classStaticPrivateFieldSpecSet.js | safe | No malicious patterns detected in this Babel helper module; it is a straightforward static private field setter with no network, filesystem, or code execution behavior. |
| helpers/esm/classStaticPrivateMethodGet.js | safe | No malicious patterns detected; the file is a small helper that asserts a class brand and returns a method reference. |
| helpers/esm/classStaticPrivateMethodSet.js | safe | Cleared by Jev triage; no further analysis needed |
| helpers/esm/construct.js | safe | No malicious patterns detected |
| helpers/esm/createClass.js | safe | No malicious patterns detected |
| helpers/esm/createForOfIteratorHelper.js | safe | The file is a standard Babel transpilation helper for iterating over iterables and contains no malicious patterns. |
| helpers/esm/createForOfIteratorHelperLoose.js | safe | No malicious patterns detected; this is a standard Babel helper for iterating objects safely. |
| helpers/esm/createSuper.js | safe | The code is a standard Babel helper for extending ES6 classes, using only safe reflection and prototype utilities with no malicious patterns. |
| helpers/esm/decorate.js | safe | No malicious patterns detected; the code is a standard Babel helper for implementing the JavaScript decorators proposal. |
| helpers/esm/defaults.js | safe | No malicious patterns detected; the code is a standard utility function for copying configurable own properties from a source object to a target object. |
| helpers/esm/defineAccessor.js | safe | This is a standard Babel helper function for defining object accessors; no malicious patterns detected. |
| helpers/esm/defineEnumerableProperties.js | safe | No malicious patterns detected; this is a standard Babel helper function for defining enumerable properties. |
| helpers/esm/defineProperty.js | safe | Legitimate Babel helper for defining object properties with no malicious patterns detected |
| helpers/esm/dispose.js | safe | No malicious patterns detected; the code is a standard polyfill/polyfill-like implementation for resource disposal (using SuppressedError) with no network, filesystem, process, or dynamic code execution behavior. |
| helpers/esm/extends.js | safe | No malicious patterns detected |
| helpers/esm/get.js | safe | This is a standard Babel helper for Reflect.get with super property fallback, containing no malicious patterns or suspicious behavior. |
| helpers/esm/getPrototypeOf.js | safe | No malicious patterns detected; this is a standard Babel helper for getPrototypeOf with no network, filesystem, process, or dynamic execution behavior. |
| helpers/esm/identity.js | safe | No malicious patterns detected |
| helpers/esm/importDeferProxy.js | safe | No malicious patterns detected |
| helpers/esm/inherits.js | safe | No malicious patterns detected; this is a standard Babel helper for prototypal inheritance. |
| helpers/esm/inheritsLoose.js | safe | No malicious patterns detected |
| helpers/esm/initializerDefineProperty.js | safe | No malicious patterns detected |
| helpers/esm/initializerWarningHelper.js | safe | No malicious patterns detected |
| helpers/esm/instanceof.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing an instanceof polyfill with no network, filesystem, process, or dynamic execution behavior. |
| helpers/esm/interopRequireDefault.js | safe | No malicious patterns detected |
| helpers/esm/interopRequireWildcard.js | safe | This is a standard Babel ESM interop helper that only performs module namespace wrapping and does not exhibit any malicious patterns. |
| helpers/esm/isNativeFunction.js | safe | No malicious patterns detected |
| helpers/esm/isNativeReflectConstruct.js | safe | This is a standard Babel helper for detecting native Reflect.construct support with no malicious patterns, network calls, filesystem access, or dynamic code execution. |
| helpers/esm/iterableToArray.js | safe | No malicious patterns detected; the code is a standard Babel helper that safely converts iterables to arrays without side effects or external access. |
| helpers/esm/iterableToArrayLimit.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays. |
| helpers/esm/jsx.js | safe | No malicious patterns detected; the code is a standard React element creation helper with no network, filesystem, process, or obfuscation concerns. |
| helpers/esm/maybeArrayLike.js | safe | No malicious patterns detected; this is a benign Babel helper for array-like handling. |
| helpers/esm/newArrowCheck.js | safe | No malicious patterns detected |
| helpers/esm/nonIterableRest.js | safe | Cleared by Jev triage; no further analysis needed |
| helpers/esm/nonIterableSpread.js | safe | Cleared by Jev triage; no further analysis needed |
| helpers/esm/nullishReceiverError.js | safe | No malicious patterns detected; the file only defines a helper that throws a TypeError. |
| helpers/esm/objectDestructuringEmpty.js | safe | No malicious patterns detected |
| helpers/esm/objectSpread.js | safe | No malicious patterns detected; the file is a standard Babel helper for object spread compatibility. |
| helpers/esm/objectSpread2.js | safe | No malicious patterns detected; this is a standard Babel helper for object spread syntax with no network, filesystem, or dynamic code execution. |
| helpers/esm/objectWithoutProperties.js | safe | No malicious patterns detected |
| helpers/esm/objectWithoutPropertiesLoose.js | safe | No malicious patterns detected |
| helpers/esm/possibleConstructorReturn.js | safe | No malicious patterns detected |
| helpers/esm/readOnlyError.js | safe | The file contains a trivial Babel-style helper that throws a TypeError for read-only property assignments, with no network, filesystem, process, credential, or obfuscation concerns. |
| helpers/esm/regenerator.js | safe | This is a standard Babel regenerator-runtime helper that contains no malicious patterns, network activity, environment access, or dynamic code execution. |
| helpers/esm/regeneratorAsync.js | safe | No malicious patterns detected |
| helpers/esm/regeneratorAsyncGen.js | safe | No malicious patterns detected; the file is a small, standard ESM wrapper for regenerator async generators and only imports local helper modules. |
| helpers/esm/regeneratorAsyncIterator.js | safe | No malicious patterns detected; the file is a standard Babel regenerator runtime helper implementing async iterator support without network, filesystem, process, or dynamic code execution behavior. |
| helpers/esm/regeneratorDefine.js | safe | No malicious patterns detected; the code is a standard regenerator runtime helper for defining properties. |
| helpers/esm/regeneratorKeys.js | safe | The code is a standard Babel/regenerator helper that iterates over object keys; no malicious patterns, network, filesystem, or dynamic execution concerns were found. |
| helpers/esm/regeneratorRuntime.js | safe | No malicious patterns detected |
| helpers/esm/regeneratorValues.js | safe | This is a standard Babel helper for iterating regenerator values with no malicious patterns, network activity, or suspicious behavior. |
| helpers/esm/set.js | safe | No malicious patterns detected |
| helpers/esm/setFunctionName.js | safe | No malicious patterns detected; the code is a straightforward utility for setting function names with safe property definition and error handling. |
| helpers/esm/setPrototypeOf.js | safe | No malicious patterns detected; this is a standard Babel helper for setting an object's prototype. |
| helpers/esm/skipFirstGeneratorNext.js | safe | No malicious patterns detected; the code is a standard helper for skipping the first yield of a generator function. |
| helpers/esm/slicedToArray.js | safe | No malicious patterns detected |
| helpers/esm/superPropBase.js | safe | No malicious patterns detected; the file is a standard Babel helper for accessing superclass properties. |
| helpers/esm/superPropGet.js | safe | No malicious patterns detected; the file is a benign Babel helper for accessing superclass properties. |
| helpers/esm/superPropSet.js | safe | No malicious patterns detected |
| helpers/esm/taggedTemplateLiteral.js | safe | No malicious patterns detected |
| helpers/esm/taggedTemplateLiteralLoose.js | safe | No malicious patterns detected |
| helpers/esm/tdz.js | safe | No malicious patterns detected |
| helpers/esm/temporalRef.js | safe | No malicious patterns detected |
| helpers/esm/temporalUndefined.js | safe | No malicious patterns detected |
| helpers/esm/toArray.js | safe | No malicious patterns detected; the file implements a standard Babel helper for converting iterables to arrays with no suspicious behavior. |
| helpers/esm/toConsumableArray.js | safe | Cleared by Jev triage; no further analysis needed |
| helpers/esm/toPrimitive.js | safe | No malicious patterns detected |
| helpers/esm/toPropertyKey.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting values to property keys. |
| helpers/esm/toSetter.js | safe | No malicious patterns detected |
| helpers/esm/tsRewriteRelativeImportExtensions.js | safe | No malicious patterns detected; the code is a benign utility that rewrites TypeScript import extensions to JavaScript equivalents. |
| helpers/esm/typeof.js | safe | No malicious patterns detected |
| helpers/esm/unsupportedIterableToArray.js | safe | No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays. |
| helpers/esm/using.js | safe | No malicious patterns detected; this is a standard Babel helper implementing the TC39 'using' declaration disposal mechanism using Symbol.dispose/Symbol.asyncDispose. |
| helpers/esm/usingCtx.js | safe | This is a standard Babel/TypeScript helper for transpiling the 'using' declarations proposal (explicit resource management); it contains no malicious patterns such as network access, credential harvesting, obfuscation, or code execution. |
| helpers/esm/wrapAsyncGenerator.js | safe | No malicious patterns detected; the file is a standard Babel async generator helper with no network, filesystem, process, or eval activity. |
| helpers/esm/wrapNativeSuper.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper implementing _wrapNativeSuper with no network, filesystem, process, or dynamic code execution activity. |
| helpers/esm/wrapRegExp.js | safe | No malicious patterns detected; this is a legitimate Babel helper for extending RegExp with named groups. |
| helpers/esm/writeOnlyError.js | safe | The file contains a trivial helper function that throws a TypeError for write-only property access, with no malicious patterns or suspicious behavior detected. |
| helpers/extends.js | safe | No malicious patterns detected |
| helpers/get.js | safe | No malicious patterns detected; this is a standard Babel helper for ES6 Reflect.get/super property access with no network, filesystem, or execution risks. |
| helpers/getPrototypeOf.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for getting an object's prototype. |
| helpers/identity.js | safe | The file contains a simple identity function with standard module exports and no malicious patterns. |
| helpers/importDeferProxy.js | safe | No malicious patterns detected |
| helpers/inherits.js | safe | No malicious patterns detected |
| helpers/inheritsLoose.js | safe | No malicious patterns detected |
| helpers/initializerDefineProperty.js | safe | This is a standard Babel helper function that safely defines object properties with no malicious patterns. |
| helpers/initializerWarningHelper.js | safe | This is a standard Babel runtime helper function that only throws an error when decorators are misconfigured; no malicious patterns detected. |
| helpers/instanceof.js | safe | No malicious patterns detected |
| helpers/interopRequireDefault.js | safe | No malicious patterns detected |
| helpers/interopRequireWildcard.js | safe | No malicious patterns detected; this is a standard Babel helper for interopRequireWildcard with no network, filesystem, process, or dynamic execution behavior. |
| helpers/isNativeFunction.js | safe | The file contains only a standard utility function to detect native functions via Function.prototype.toString, with no malicious patterns, network activity, file access, or code execution. |
| helpers/isNativeReflectConstruct.js | safe | The code is a standard Babel helper for detecting native Reflect.construct support, with no malicious patterns, network activity, or suspicious behavior. |
| helpers/iterableToArray.js | safe | No malicious patterns detected |
| helpers/iterableToArrayLimit.js | safe | No malicious patterns detected; this is a standard Babel helper for safely converting iterables to arrays with length limits. |
| helpers/jsx.js | safe | This is a standard Babel/React JSX runtime helper that creates React elements; no malicious patterns, network calls, file access, or dynamic code execution were found. |
| helpers/maybeArrayLike.js | safe | No malicious patterns detected |
| helpers/newArrowCheck.js | safe | No malicious patterns detected; this is a standard Babel helper for arrow function instantiation checks. |
| helpers/nonIterableRest.js | safe | No malicious patterns detected |
| helpers/nonIterableSpread.js | safe | No malicious patterns detected |
| helpers/nullishReceiverError.js | safe | No malicious patterns detected |
| helpers/objectDestructuringEmpty.js | safe | No malicious patterns detected; the code is a standard Babel helper for throwing a TypeError on null/undefined destructuring. |
| helpers/objectSpread.js | safe | This is a standard Babel helper for object spread syntax with no malicious patterns detected |
| helpers/objectSpread2.js | safe | No malicious patterns detected |
| helpers/objectWithoutProperties.js | safe | No malicious patterns detected |
| helpers/objectWithoutPropertiesLoose.js | safe | No malicious patterns detected; the code is a standard Babel helper that safely copies own enumerable properties excluding specified keys. |
| helpers/possibleConstructorReturn.js | safe | This is a standard Babel helper function for handling derived constructor return values, containing no malicious patterns, network calls, file system access, or dynamic code execution. |
| helpers/readOnlyError.js | safe | No malicious patterns detected |
| helpers/regenerator.js | safe | This is a legitimate Babel regenerator-runtime helper with no malicious patterns; it contains no network, filesystem, process, credential, or obfuscated/dynamic code execution concerns. |
| helpers/regeneratorAsync.js | safe | This is a standard Babel regenerator runtime helper with no malicious patterns; it only performs a relative require and an async iterator helper. |
| helpers/regeneratorAsyncGen.js | safe | No malicious patterns detected; the file only imports local dependencies and defines a small wrapper function for async generators. |
| helpers/regeneratorAsyncIterator.js | safe | No malicious patterns detected |
| helpers/regeneratorDefine.js | safe | This is a standard Babel regenerator runtime helper for defining properties with no malicious patterns, network access, file system operations, or code execution. |
| helpers/regeneratorKeys.js | safe | No malicious patterns detected |
| helpers/regeneratorRuntime.js | safe | No malicious patterns detected |
| helpers/regeneratorValues.js | safe | No malicious patterns detected |
| helpers/set.js | safe | No malicious patterns detected; the code is a standard Babel helper for property setting using Reflect.set or a fallback implementation. |
| helpers/setFunctionName.js | safe | No malicious patterns detected; the code is a benign utility for setting function names with a safe try/catch and no external operations. |
| helpers/setPrototypeOf.js | safe | This is a standard Babel helper function for setting object prototypes with no malicious patterns detected. |
| helpers/skipFirstGeneratorNext.js | safe | The code is a benign utility function that wraps a generator to skip its first yield, with no malicious patterns detected. |
| helpers/slicedToArray.js | safe | This is a Babel helper function for array destructuring with no malicious patterns, network activity, environment access, or dynamic code execution. |
| helpers/superPropBase.js | safe | This is a standard Babel helper function for accessing super class properties; no malicious patterns detected. |
| helpers/superPropGet.js | safe | No malicious patterns detected |
| helpers/superPropSet.js | safe | No malicious patterns detected; the file is a Babel-generated helper for super property assignment with only local module requires and no external I/O, dynamic execution, or install-time behavior. |
| helpers/taggedTemplateLiteral.js | safe | The file is a standard Babel helper for tagged template literals and contains no malicious patterns. |
| helpers/taggedTemplateLiteralLoose.js | safe | No malicious patterns detected |
| helpers/tdz.js | safe | No malicious patterns detected |
| helpers/temporalRef.js | safe | The code is a standard Babel helper for temporal dead zone (TDZ) references, with no malicious patterns, network activity, file system access, or dynamic code execution. |
| helpers/temporalUndefined.js | safe | No malicious patterns detected |
| helpers/toArray.js | safe | No malicious patterns detected |
| helpers/toConsumableArray.js | safe | No malicious patterns detected |
| helpers/toPrimitive.js | safe | No malicious patterns detected; the code is a standard Babel helper for ToPrimitive conversion. |
| helpers/toPropertyKey.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting values to property keys. |
| helpers/toSetter.js | safe | No malicious patterns detected; the code is a standard Babel helper for creating setter functions via Object.defineProperty. |
| helpers/tsRewriteRelativeImportExtensions.js | safe | The code is a benign utility function that rewrites TypeScript import extensions to JavaScript equivalents, with no network, filesystem, process, or dynamic execution activity. |
| helpers/typeof.js | safe | No malicious patterns detected |
| helpers/unsupportedIterableToArray.js | safe | The file is a standard Babel helper function for iterable conversion with no malicious patterns or security concerns. |
| helpers/using.js | safe | This is a legitimate Babel helper function implementing the 'using' declaration spec, with no malicious patterns detected. |
| helpers/usingCtx.js | safe | This is a standard Babel helper implementation for the JavaScript 'using' declarations (explicit resource management) proposal; it contains no network, filesystem, process, or obfuscated code patterns. |
| helpers/wrapAsyncGenerator.js | safe | No malicious patterns detected; the code is a standard Babel/TypeScript async generator runtime helper with no network, file, process, or dynamic code execution. |
| helpers/wrapNativeSuper.js | safe | No malicious patterns detected; the code is a standard Babel helper for wrapping native super classes without any obfuscation, network, filesystem, or process manipulation. |
| helpers/wrapRegExp.js | safe | This is a legitimate Babel helper for extending RegExp with named capture groups; no malicious patterns detected. |
| helpers/writeOnlyError.js | safe | No malicious patterns detected; the file contains a simple Babel helper that throws a TypeError for write-only property access. |
Affected version ranges
None of the 2 scanned versions of @babel/runtime are flagged high or critical. The latest scanned version, 8.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 7.29.2 – 8.0.0 | Not scanned | 3 | >=7.29.2 <=8.0.0 | |
| 7.28.4 – 7.28.6 | Needs review | 2 | >=7.28.4 <=7.28.6 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @babel/runtime
Frequently asked questions
Is @babel/runtime safe to use?
No confirmed malware was found in @babel/runtime@7.28.6, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does @babel/runtime contain malware?
No malware was identified in @babel/runtime@7.28.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @babel/runtime checked?
Togoder Security downloaded the published npm package and had an AI model read its 245 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @babel/runtime together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @babel/runtime@7.28.6, cost nothing.