Togoder security

npm package security report

@babel/runtime@7.28.6 security report

Risky patterns found that deserve a look.

Needs review Version 7.28.6 Files reviewed 245 Size 200.8 KB Scanned

Summary

Togoder Security scanned the npm package @babel/runtime@7.28.6 on Oct 6, 2026. An AI review of 245 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

global namespace pollution

NPS-807A3722A0D7

Attempts to assign regeneratorRuntime to the global scope and explicitly sets globalThis.regeneratorRuntime. This pollutes the global environment but is the documented behavior of the Babel regenerator runtime compatibility shim.

regenerator/index.js:7
low

dynamic code execution

NPS-9EFB544298AB

Uses Function('r', 'regeneratorRuntime = r')(runtime) as a fallback to intentionally assign a global variable in strict-mode environments where implicit global assignment fails. This is not obfuscated or input-driven, but Function() construction is a dynamic code execution primitive and can be flagged by security scanners.

regenerator/index.js:11

Files reviewed

FileVerdictWhat the reviewer saw
regenerator/index.js medium This is a standard Babel regenerator runtime compatibility shim; it only uses Function() for a deliberate global assignment fallback and shows no signs of exfiltration, credential theft, backdoors, or other malicious behavior.
helpers/AwaitValue.js safe No malicious patterns detected
helpers/OverloadYield.js safe No malicious patterns detected
helpers/applyDecoratedDescriptor.js safe No malicious patterns detected
helpers/applyDecs.js safe No malicious patterns detected in this Babel decorators helper, which contains only legitimate decorator transformation logic without network, file system, process, or credential access.
helpers/applyDecs2203.js safe No malicious patterns detected; this is a standard Babel decorator-runtime helper implementing ES decorators with no network, filesystem, process, or dynamic-evaluation behavior.
helpers/applyDecs2203R.js safe Legitimate Babel decorators helper implementation with no malicious patterns detected.
helpers/applyDecs2301.js safe No malicious patterns detected; the file is a standard Babel decorators helper implementing ES decorator semantics.
helpers/applyDecs2305.js safe No malicious patterns detected; this is a standard Babel helper for decorator semantics with no network, filesystem, process, or obfuscated code.
helpers/applyDecs2311.js safe This is a Babel helper for decorator metadata (applyDecs2311) with no malicious patterns, network calls, environment access, or dynamic code execution.
helpers/arrayLikeToArray.js safe This is a benign Babel helper function that converts array-like objects to arrays with no malicious patterns detected.
helpers/arrayWithHoles.js safe No malicious patterns detected
helpers/arrayWithoutHoles.js safe No malicious patterns detected
helpers/assertClassBrand.js safe No malicious patterns detected
helpers/assertThisInitialized.js safe No malicious patterns detected; the file is a standard Babel helper that validates this initialization.
helpers/asyncGeneratorDelegate.js safe No malicious patterns detected; this is a standard Babel helper for async generator delegation.
helpers/asyncIterator.js safe No malicious patterns detected; this is a standard Babel helper for async iteration with no network, filesystem, process, or dynamic code execution activity.
helpers/asyncToGenerator.js safe No malicious patterns detected; this is the standard Babel asyncToGenerator helper for converting async functions to generator-based promise chains.
helpers/awaitAsyncGenerator.js safe No malicious patterns detected; the file is a simple Babel helper that wraps a value in an OverloadYield object without any dangerous operations.
helpers/callSuper.js safe This is a standard Babel helper function for calling super constructors, with no malicious patterns detected.
helpers/checkInRHS.js safe No malicious patterns detected
helpers/checkPrivateRedeclaration.js safe No malicious patterns detected; the code is a standard Babel helper for private field redeclaration checks with no network, filesystem, process, or dynamic execution behavior.
helpers/classApplyDescriptorDestructureSet.js safe No malicious patterns detected; the file is a standard Babel helper for private field destructuring assignment.
helpers/classApplyDescriptorGet.js safe No malicious patterns detected
helpers/classApplyDescriptorSet.js safe No malicious patterns detected; the code is a standard Babel helper for setting private class fields with proper validation and no external interactions.
Show 220 more files
FileVerdictWhat the reviewer saw
helpers/classCallCheck.js safe No malicious patterns detected
helpers/classCheckPrivateStaticAccess.js safe No malicious patterns detected
helpers/classCheckPrivateStaticFieldDescriptor.js safe No malicious patterns detected; the file is a benign Babel helper function for checking private static field declarations.
helpers/classExtractFieldDescriptor.js safe No malicious patterns detected; the file is a simple Babel helper that delegates to another local module.
helpers/classNameTDZError.js safe No malicious patterns detected
helpers/classPrivateFieldDestructureSet.js safe No malicious patterns detected
helpers/classPrivateFieldGet.js safe No malicious patterns detected; this is a standard Babel helper for accessing private class fields.
helpers/classPrivateFieldGet2.js safe No malicious patterns detected; this is a standard Babel helper for private field access with no external, network, filesystem, or process activity.
helpers/classPrivateFieldInitSpec.js safe This is a standard Babel helper for private field initialization with no malicious patterns detected.
helpers/classPrivateFieldLooseBase.js safe No malicious patterns detected; the file is a standard Babel runtime helper for private field access checks.
helpers/classPrivateFieldLooseKey.js safe No malicious patterns detected in this small utility module that generates unique private field key names.
helpers/classPrivateFieldSet.js safe No malicious patterns detected; this is a standard Babel helper for setting private class fields.
helpers/classPrivateFieldSet2.js safe No malicious patterns detected; the helper performs a standard private field set using class brand assertion without any external calls, dynamic execution, or I/O.
helpers/classPrivateGetter.js safe No malicious patterns detected; the file is a standard Babel runtime helper for private getter access.
helpers/classPrivateMethodGet.js safe No malicious patterns detected; this is a standard Babel helper for private method access.
helpers/classPrivateMethodInitSpec.js safe No malicious patterns detected
helpers/classPrivateMethodSet.js safe The file contains a standard Babel helper that throws a TypeError when attempting to reassign a private method; no malicious patterns detected.
helpers/classPrivateSetter.js safe No malicious patterns detected
helpers/classStaticPrivateFieldDestructureSet.js safe No malicious patterns detected; this is a standard Babel helper for private static field destructuring assignment.
helpers/classStaticPrivateFieldSpecGet.js safe No malicious patterns detected; this is a standard Babel helper for private static field access with no network, filesystem, process, or dynamic code execution behavior.
helpers/classStaticPrivateFieldSpecSet.js safe No malicious patterns detected
helpers/classStaticPrivateMethodGet.js safe No malicious patterns detected; the file is a standard Babel helper for accessing static private methods.
helpers/classStaticPrivateMethodSet.js safe No malicious patterns detected in this Babel runtime helper that only throws a TypeError for read-only static private field assignments.
helpers/construct.js safe No malicious patterns detected; this is a standard Babel helper for Reflect.construct fallback.
helpers/createClass.js safe No malicious patterns detected; the code is a standard Babel helper for defining class properties.
helpers/createForOfIteratorHelper.js safe No malicious patterns detected; this is a standard Babel transpilation helper for for-of iteration.
helpers/createForOfIteratorHelperLoose.js safe No malicious patterns detected; the file is a standard Babel helper for loose for-of iteration with no network, filesystem, process, or dynamic code execution behavior.
helpers/createSuper.js safe No malicious patterns detected; the file is a standard Babel runtime helper for creating superclass constructors.
helpers/decorate.js safe This is a standard Babel helper for JavaScript decorator transforms with no malicious patterns, network calls, credential access, or dynamic code execution.
helpers/defaults.js safe No malicious patterns detected; the code is a standard utility for copying default properties, with no network, filesystem, or process activity.
helpers/defineAccessor.js safe No malicious patterns detected; the code is a standard Babel helper for defining object properties.
helpers/defineEnumerableProperties.js safe This is a standard Babel helper function that defines enumerable properties; it contains no malicious patterns, network activity, credential access, dynamic code execution, or lifecycle scripts.
helpers/defineProperty.js safe No malicious patterns detected
helpers/dispose.js safe No malicious patterns detected; the code is a standard Babel helper implementing the explicit resource management dispose protocol with SuppressedError support, containing no network, filesystem, process, or dynamic execution behavior.
helpers/esm/AwaitValue.js safe No malicious patterns detected
helpers/esm/OverloadYield.js safe No malicious patterns detected; the file defines a simple constructor function and exports it as default.
helpers/esm/applyDecoratedDescriptor.js safe No malicious patterns detected
helpers/esm/applyDecs.js safe No malicious patterns detected; the code is a standard Babel helper for implementing decorators and metadata, with no network, filesystem, process execution, or obfuscated behavior.
helpers/esm/applyDecs2203.js safe This is a standard Babel helper module implementing the decorators proposal (applyDecs2203) with no network, filesystem, process, or dynamic code execution patterns.
helpers/esm/applyDecs2203R.js safe This is a legitimate Babel helper for decorator transpilation with no malicious patterns detected.
helpers/esm/applyDecs2301.js safe No malicious patterns detected
helpers/esm/applyDecs2305.js safe This is a legitimate Babel helper implementing the ES decorators proposal (applyDecs2305) with no malicious patterns, network access, file system manipulation, or obfuscated code.
helpers/esm/applyDecs2311.js safe No malicious patterns detected
helpers/esm/arrayLikeToArray.js safe No malicious patterns detected
helpers/esm/arrayWithHoles.js safe No malicious patterns detected
helpers/esm/arrayWithoutHoles.js safe No malicious patterns detected
helpers/esm/assertClassBrand.js safe No malicious patterns detected
helpers/esm/assertThisInitialized.js safe No malicious patterns detected
helpers/esm/asyncGeneratorDelegate.js safe No malicious patterns detected; this is a standard Babel helper for async generator delegation.
helpers/esm/asyncIterator.js safe No malicious patterns detected; the file is a standard Babel runtime helper for async iterator support with no network, filesystem, or code execution behavior.
helpers/esm/asyncToGenerator.js safe No malicious patterns detected; the code is a standard Babel async-to-generator helper with no network, filesystem, process, or obfuscation activity.
helpers/esm/awaitAsyncGenerator.js safe The file is a trivial Babel helper that wraps a value in an OverloadYield object with no malicious behavior or side effects.
helpers/esm/callSuper.js safe No malicious patterns detected; this is a standard Babel transpilation helper for calling super constructors with no external network, filesystem, or code execution activity.
helpers/esm/checkInRHS.js safe No malicious patterns detected; the file is a standard Babel helper function for validating the right-hand side of 'in' operators.
helpers/esm/checkPrivateRedeclaration.js safe No malicious patterns detected
helpers/esm/classApplyDescriptorDestructureSet.js safe No malicious patterns detected
helpers/esm/classApplyDescriptorGet.js safe No malicious patterns detected; the code only provides a simple helper for accessing class descriptor values via getters or direct values.
helpers/esm/classApplyDescriptorSet.js safe This is a standard Babel helper function for applying values to class private fields with no malicious patterns detected.
helpers/esm/classCallCheck.js safe No malicious patterns detected
helpers/esm/classCheckPrivateStaticAccess.js safe Cleared by Jev triage; no further analysis needed
helpers/esm/classCheckPrivateStaticFieldDescriptor.js safe No malicious patterns detected; the code is a simple helper function that throws a TypeError when a private static field is accessed before its declaration.
helpers/esm/classExtractFieldDescriptor.js safe No malicious patterns detected
helpers/esm/classNameTDZError.js safe No malicious patterns detected
helpers/esm/classPrivateFieldDestructureSet.js safe No malicious patterns detected
helpers/esm/classPrivateFieldGet.js safe No malicious patterns detected; the file is a standard Babel runtime helper for private class field access with no suspicious behavior.
helpers/esm/classPrivateFieldGet2.js safe No malicious patterns detected; the code is a legitimate Babel helper for private field access with no suspicious behavior.
helpers/esm/classPrivateFieldInitSpec.js safe This is a standard Babel helper for initializing private class fields; it performs no network, filesystem, or process operations and contains no malicious patterns.
helpers/esm/classPrivateFieldLooseBase.js safe This is a standard Babel helper function for private field access with no malicious patterns.
helpers/esm/classPrivateFieldLooseKey.js safe No malicious patterns detected
helpers/esm/classPrivateFieldSet.js safe No malicious patterns detected
helpers/esm/classPrivateFieldSet2.js safe This is a standard Babel transpilation helper for setting private class fields, with no malicious patterns or security concerns.
helpers/esm/classPrivateGetter.js safe No malicious patterns detected
helpers/esm/classPrivateMethodGet.js safe No malicious patterns detected
helpers/esm/classPrivateMethodInitSpec.js safe No malicious patterns detected
helpers/esm/classPrivateMethodSet.js safe Cleared by Jev triage; no further analysis needed
helpers/esm/classPrivateSetter.js safe No malicious patterns detected
helpers/esm/classStaticPrivateFieldDestructureSet.js safe No malicious patterns detected
helpers/esm/classStaticPrivateFieldSpecGet.js safe No malicious patterns detected; this is a standard Babel helper for accessing private static fields.
helpers/esm/classStaticPrivateFieldSpecSet.js safe No malicious patterns detected in this Babel helper module; it is a straightforward static private field setter with no network, filesystem, or code execution behavior.
helpers/esm/classStaticPrivateMethodGet.js safe No malicious patterns detected; the file is a small helper that asserts a class brand and returns a method reference.
helpers/esm/classStaticPrivateMethodSet.js safe Cleared by Jev triage; no further analysis needed
helpers/esm/construct.js safe No malicious patterns detected
helpers/esm/createClass.js safe No malicious patterns detected
helpers/esm/createForOfIteratorHelper.js safe The file is a standard Babel transpilation helper for iterating over iterables and contains no malicious patterns.
helpers/esm/createForOfIteratorHelperLoose.js safe No malicious patterns detected; this is a standard Babel helper for iterating objects safely.
helpers/esm/createSuper.js safe The code is a standard Babel helper for extending ES6 classes, using only safe reflection and prototype utilities with no malicious patterns.
helpers/esm/decorate.js safe No malicious patterns detected; the code is a standard Babel helper for implementing the JavaScript decorators proposal.
helpers/esm/defaults.js safe No malicious patterns detected; the code is a standard utility function for copying configurable own properties from a source object to a target object.
helpers/esm/defineAccessor.js safe This is a standard Babel helper function for defining object accessors; no malicious patterns detected.
helpers/esm/defineEnumerableProperties.js safe No malicious patterns detected; this is a standard Babel helper function for defining enumerable properties.
helpers/esm/defineProperty.js safe Legitimate Babel helper for defining object properties with no malicious patterns detected
helpers/esm/dispose.js safe No malicious patterns detected; the code is a standard polyfill/polyfill-like implementation for resource disposal (using SuppressedError) with no network, filesystem, process, or dynamic code execution behavior.
helpers/esm/extends.js safe No malicious patterns detected
helpers/esm/get.js safe This is a standard Babel helper for Reflect.get with super property fallback, containing no malicious patterns or suspicious behavior.
helpers/esm/getPrototypeOf.js safe No malicious patterns detected; this is a standard Babel helper for getPrototypeOf with no network, filesystem, process, or dynamic execution behavior.
helpers/esm/identity.js safe No malicious patterns detected
helpers/esm/importDeferProxy.js safe No malicious patterns detected
helpers/esm/inherits.js safe No malicious patterns detected; this is a standard Babel helper for prototypal inheritance.
helpers/esm/inheritsLoose.js safe No malicious patterns detected
helpers/esm/initializerDefineProperty.js safe No malicious patterns detected
helpers/esm/initializerWarningHelper.js safe No malicious patterns detected
helpers/esm/instanceof.js safe No malicious patterns detected; the code is a standard Babel helper implementing an instanceof polyfill with no network, filesystem, process, or dynamic execution behavior.
helpers/esm/interopRequireDefault.js safe No malicious patterns detected
helpers/esm/interopRequireWildcard.js safe This is a standard Babel ESM interop helper that only performs module namespace wrapping and does not exhibit any malicious patterns.
helpers/esm/isNativeFunction.js safe No malicious patterns detected
helpers/esm/isNativeReflectConstruct.js safe This is a standard Babel helper for detecting native Reflect.construct support with no malicious patterns, network calls, filesystem access, or dynamic code execution.
helpers/esm/iterableToArray.js safe No malicious patterns detected; the code is a standard Babel helper that safely converts iterables to arrays without side effects or external access.
helpers/esm/iterableToArrayLimit.js safe No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays.
helpers/esm/jsx.js safe No malicious patterns detected; the code is a standard React element creation helper with no network, filesystem, process, or obfuscation concerns.
helpers/esm/maybeArrayLike.js safe No malicious patterns detected; this is a benign Babel helper for array-like handling.
helpers/esm/newArrowCheck.js safe No malicious patterns detected
helpers/esm/nonIterableRest.js safe Cleared by Jev triage; no further analysis needed
helpers/esm/nonIterableSpread.js safe Cleared by Jev triage; no further analysis needed
helpers/esm/nullishReceiverError.js safe No malicious patterns detected; the file only defines a helper that throws a TypeError.
helpers/esm/objectDestructuringEmpty.js safe No malicious patterns detected
helpers/esm/objectSpread.js safe No malicious patterns detected; the file is a standard Babel helper for object spread compatibility.
helpers/esm/objectSpread2.js safe No malicious patterns detected; this is a standard Babel helper for object spread syntax with no network, filesystem, or dynamic code execution.
helpers/esm/objectWithoutProperties.js safe No malicious patterns detected
helpers/esm/objectWithoutPropertiesLoose.js safe No malicious patterns detected
helpers/esm/possibleConstructorReturn.js safe No malicious patterns detected
helpers/esm/readOnlyError.js safe The file contains a trivial Babel-style helper that throws a TypeError for read-only property assignments, with no network, filesystem, process, credential, or obfuscation concerns.
helpers/esm/regenerator.js safe This is a standard Babel regenerator-runtime helper that contains no malicious patterns, network activity, environment access, or dynamic code execution.
helpers/esm/regeneratorAsync.js safe No malicious patterns detected
helpers/esm/regeneratorAsyncGen.js safe No malicious patterns detected; the file is a small, standard ESM wrapper for regenerator async generators and only imports local helper modules.
helpers/esm/regeneratorAsyncIterator.js safe No malicious patterns detected; the file is a standard Babel regenerator runtime helper implementing async iterator support without network, filesystem, process, or dynamic code execution behavior.
helpers/esm/regeneratorDefine.js safe No malicious patterns detected; the code is a standard regenerator runtime helper for defining properties.
helpers/esm/regeneratorKeys.js safe The code is a standard Babel/regenerator helper that iterates over object keys; no malicious patterns, network, filesystem, or dynamic execution concerns were found.
helpers/esm/regeneratorRuntime.js safe No malicious patterns detected
helpers/esm/regeneratorValues.js safe This is a standard Babel helper for iterating regenerator values with no malicious patterns, network activity, or suspicious behavior.
helpers/esm/set.js safe No malicious patterns detected
helpers/esm/setFunctionName.js safe No malicious patterns detected; the code is a straightforward utility for setting function names with safe property definition and error handling.
helpers/esm/setPrototypeOf.js safe No malicious patterns detected; this is a standard Babel helper for setting an object's prototype.
helpers/esm/skipFirstGeneratorNext.js safe No malicious patterns detected; the code is a standard helper for skipping the first yield of a generator function.
helpers/esm/slicedToArray.js safe No malicious patterns detected
helpers/esm/superPropBase.js safe No malicious patterns detected; the file is a standard Babel helper for accessing superclass properties.
helpers/esm/superPropGet.js safe No malicious patterns detected; the file is a benign Babel helper for accessing superclass properties.
helpers/esm/superPropSet.js safe No malicious patterns detected
helpers/esm/taggedTemplateLiteral.js safe No malicious patterns detected
helpers/esm/taggedTemplateLiteralLoose.js safe No malicious patterns detected
helpers/esm/tdz.js safe No malicious patterns detected
helpers/esm/temporalRef.js safe No malicious patterns detected
helpers/esm/temporalUndefined.js safe No malicious patterns detected
helpers/esm/toArray.js safe No malicious patterns detected; the file implements a standard Babel helper for converting iterables to arrays with no suspicious behavior.
helpers/esm/toConsumableArray.js safe Cleared by Jev triage; no further analysis needed
helpers/esm/toPrimitive.js safe No malicious patterns detected
helpers/esm/toPropertyKey.js safe No malicious patterns detected; the code is a standard Babel helper for converting values to property keys.
helpers/esm/toSetter.js safe No malicious patterns detected
helpers/esm/tsRewriteRelativeImportExtensions.js safe No malicious patterns detected; the code is a benign utility that rewrites TypeScript import extensions to JavaScript equivalents.
helpers/esm/typeof.js safe No malicious patterns detected
helpers/esm/unsupportedIterableToArray.js safe No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays.
helpers/esm/using.js safe No malicious patterns detected; this is a standard Babel helper implementing the TC39 'using' declaration disposal mechanism using Symbol.dispose/Symbol.asyncDispose.
helpers/esm/usingCtx.js safe This is a standard Babel/TypeScript helper for transpiling the 'using' declarations proposal (explicit resource management); it contains no malicious patterns such as network access, credential harvesting, obfuscation, or code execution.
helpers/esm/wrapAsyncGenerator.js safe No malicious patterns detected; the file is a standard Babel async generator helper with no network, filesystem, process, or eval activity.
helpers/esm/wrapNativeSuper.js safe No malicious patterns detected; the file is a standard Babel runtime helper implementing _wrapNativeSuper with no network, filesystem, process, or dynamic code execution activity.
helpers/esm/wrapRegExp.js safe No malicious patterns detected; this is a legitimate Babel helper for extending RegExp with named groups.
helpers/esm/writeOnlyError.js safe The file contains a trivial helper function that throws a TypeError for write-only property access, with no malicious patterns or suspicious behavior detected.
helpers/extends.js safe No malicious patterns detected
helpers/get.js safe No malicious patterns detected; this is a standard Babel helper for ES6 Reflect.get/super property access with no network, filesystem, or execution risks.
helpers/getPrototypeOf.js safe No malicious patterns detected; the file is a standard Babel runtime helper for getting an object's prototype.
helpers/identity.js safe The file contains a simple identity function with standard module exports and no malicious patterns.
helpers/importDeferProxy.js safe No malicious patterns detected
helpers/inherits.js safe No malicious patterns detected
helpers/inheritsLoose.js safe No malicious patterns detected
helpers/initializerDefineProperty.js safe This is a standard Babel helper function that safely defines object properties with no malicious patterns.
helpers/initializerWarningHelper.js safe This is a standard Babel runtime helper function that only throws an error when decorators are misconfigured; no malicious patterns detected.
helpers/instanceof.js safe No malicious patterns detected
helpers/interopRequireDefault.js safe No malicious patterns detected
helpers/interopRequireWildcard.js safe No malicious patterns detected; this is a standard Babel helper for interopRequireWildcard with no network, filesystem, process, or dynamic execution behavior.
helpers/isNativeFunction.js safe The file contains only a standard utility function to detect native functions via Function.prototype.toString, with no malicious patterns, network activity, file access, or code execution.
helpers/isNativeReflectConstruct.js safe The code is a standard Babel helper for detecting native Reflect.construct support, with no malicious patterns, network activity, or suspicious behavior.
helpers/iterableToArray.js safe No malicious patterns detected
helpers/iterableToArrayLimit.js safe No malicious patterns detected; this is a standard Babel helper for safely converting iterables to arrays with length limits.
helpers/jsx.js safe This is a standard Babel/React JSX runtime helper that creates React elements; no malicious patterns, network calls, file access, or dynamic code execution were found.
helpers/maybeArrayLike.js safe No malicious patterns detected
helpers/newArrowCheck.js safe No malicious patterns detected; this is a standard Babel helper for arrow function instantiation checks.
helpers/nonIterableRest.js safe No malicious patterns detected
helpers/nonIterableSpread.js safe No malicious patterns detected
helpers/nullishReceiverError.js safe No malicious patterns detected
helpers/objectDestructuringEmpty.js safe No malicious patterns detected; the code is a standard Babel helper for throwing a TypeError on null/undefined destructuring.
helpers/objectSpread.js safe This is a standard Babel helper for object spread syntax with no malicious patterns detected
helpers/objectSpread2.js safe No malicious patterns detected
helpers/objectWithoutProperties.js safe No malicious patterns detected
helpers/objectWithoutPropertiesLoose.js safe No malicious patterns detected; the code is a standard Babel helper that safely copies own enumerable properties excluding specified keys.
helpers/possibleConstructorReturn.js safe This is a standard Babel helper function for handling derived constructor return values, containing no malicious patterns, network calls, file system access, or dynamic code execution.
helpers/readOnlyError.js safe No malicious patterns detected
helpers/regenerator.js safe This is a legitimate Babel regenerator-runtime helper with no malicious patterns; it contains no network, filesystem, process, credential, or obfuscated/dynamic code execution concerns.
helpers/regeneratorAsync.js safe This is a standard Babel regenerator runtime helper with no malicious patterns; it only performs a relative require and an async iterator helper.
helpers/regeneratorAsyncGen.js safe No malicious patterns detected; the file only imports local dependencies and defines a small wrapper function for async generators.
helpers/regeneratorAsyncIterator.js safe No malicious patterns detected
helpers/regeneratorDefine.js safe This is a standard Babel regenerator runtime helper for defining properties with no malicious patterns, network access, file system operations, or code execution.
helpers/regeneratorKeys.js safe No malicious patterns detected
helpers/regeneratorRuntime.js safe No malicious patterns detected
helpers/regeneratorValues.js safe No malicious patterns detected
helpers/set.js safe No malicious patterns detected; the code is a standard Babel helper for property setting using Reflect.set or a fallback implementation.
helpers/setFunctionName.js safe No malicious patterns detected; the code is a benign utility for setting function names with a safe try/catch and no external operations.
helpers/setPrototypeOf.js safe This is a standard Babel helper function for setting object prototypes with no malicious patterns detected.
helpers/skipFirstGeneratorNext.js safe The code is a benign utility function that wraps a generator to skip its first yield, with no malicious patterns detected.
helpers/slicedToArray.js safe This is a Babel helper function for array destructuring with no malicious patterns, network activity, environment access, or dynamic code execution.
helpers/superPropBase.js safe This is a standard Babel helper function for accessing super class properties; no malicious patterns detected.
helpers/superPropGet.js safe No malicious patterns detected
helpers/superPropSet.js safe No malicious patterns detected; the file is a Babel-generated helper for super property assignment with only local module requires and no external I/O, dynamic execution, or install-time behavior.
helpers/taggedTemplateLiteral.js safe The file is a standard Babel helper for tagged template literals and contains no malicious patterns.
helpers/taggedTemplateLiteralLoose.js safe No malicious patterns detected
helpers/tdz.js safe No malicious patterns detected
helpers/temporalRef.js safe The code is a standard Babel helper for temporal dead zone (TDZ) references, with no malicious patterns, network activity, file system access, or dynamic code execution.
helpers/temporalUndefined.js safe No malicious patterns detected
helpers/toArray.js safe No malicious patterns detected
helpers/toConsumableArray.js safe No malicious patterns detected
helpers/toPrimitive.js safe No malicious patterns detected; the code is a standard Babel helper for ToPrimitive conversion.
helpers/toPropertyKey.js safe No malicious patterns detected; the code is a standard Babel helper for converting values to property keys.
helpers/toSetter.js safe No malicious patterns detected; the code is a standard Babel helper for creating setter functions via Object.defineProperty.
helpers/tsRewriteRelativeImportExtensions.js safe The code is a benign utility function that rewrites TypeScript import extensions to JavaScript equivalents, with no network, filesystem, process, or dynamic execution activity.
helpers/typeof.js safe No malicious patterns detected
helpers/unsupportedIterableToArray.js safe The file is a standard Babel helper function for iterable conversion with no malicious patterns or security concerns.
helpers/using.js safe This is a legitimate Babel helper function implementing the 'using' declaration spec, with no malicious patterns detected.
helpers/usingCtx.js safe This is a standard Babel helper implementation for the JavaScript 'using' declarations (explicit resource management) proposal; it contains no network, filesystem, process, or obfuscated code patterns.
helpers/wrapAsyncGenerator.js safe No malicious patterns detected; the code is a standard Babel/TypeScript async generator runtime helper with no network, file, process, or dynamic code execution.
helpers/wrapNativeSuper.js safe No malicious patterns detected; the code is a standard Babel helper for wrapping native super classes without any obfuscation, network, filesystem, or process manipulation.
helpers/wrapRegExp.js safe This is a legitimate Babel helper for extending RegExp with named capture groups; no malicious patterns detected.
helpers/writeOnlyError.js safe No malicious patterns detected; the file contains a simple Babel helper that throws a TypeError for write-only property access.

Affected version ranges

None of the 2 scanned versions of @babel/runtime are flagged high or critical. The latest scanned version, 8.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

7.28.48.0.0
VersionsVerdictCountRangeTop findings
7.29.2 – 8.0.0 Not scanned 3 >=7.29.2 <=8.0.0
7.28.4 – 7.28.6 Needs review 2 >=7.28.4 <=7.28.6

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @babel/runtime

VersionVerdictFilesScanned
7.28.6 Needs review 245 Oct 6, 2026
7.28.4 Needs review 245 Oct 4, 2026

Frequently asked questions

Is @babel/runtime safe to use?

No confirmed malware was found in @babel/runtime@7.28.6, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does @babel/runtime contain malware?

No malware was identified in @babel/runtime@7.28.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @babel/runtime checked?

Togoder Security downloaded the published npm package and had an AI model read its 245 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @babel/runtime together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @babel/runtime@7.28.6, cost nothing.

Related security reports