# @babel/runtime@7.28.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:10:43.000Z
- Files reviewed: 245
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/@babel/runtime@7.28.6
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @babel/runtime@7.28.6 on Oct 6, 2026. An AI review of 245 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] global namespace pollution

Finding ID: `NPS-807A3722A0D7`

File: `regenerator/index.js:7`

Attempts to assign regeneratorRuntime to the global scope and explicitly sets globalThis.regeneratorRuntime. This pollutes the global environment but is the documented behavior of the Babel regenerator runtime compatibility shim.

### [low] dynamic code execution

Finding ID: `NPS-9EFB544298AB`

File: `regenerator/index.js:11`

Uses Function('r', 'regeneratorRuntime = r')(runtime) as a fallback to intentionally assign a global variable in strict-mode environments where implicit global assignment fails. This is not obfuscated or input-driven, but Function() construction is a dynamic code execution primitive and can be flagged by security scanners.

## Files reviewed

- `regenerator/index.js` (medium): This is a standard Babel regenerator runtime compatibility shim; it only uses Function() for a deliberate global assignment fallback and shows no signs of exfiltration, credential theft, backdoors, or other malicious behavior.
- `helpers/AwaitValue.js` (safe): No malicious patterns detected
- `helpers/OverloadYield.js` (safe): No malicious patterns detected
- `helpers/applyDecoratedDescriptor.js` (safe): No malicious patterns detected
- `helpers/applyDecs.js` (safe): No malicious patterns detected in this Babel decorators helper, which contains only legitimate decorator transformation logic without network, file system, process, or credential access.
- `helpers/applyDecs2203.js` (safe): No malicious patterns detected; this is a standard Babel decorator-runtime helper implementing ES decorators with no network, filesystem, process, or dynamic-evaluation behavior.
- `helpers/applyDecs2203R.js` (safe): Legitimate Babel decorators helper implementation with no malicious patterns detected.
- `helpers/applyDecs2301.js` (safe): No malicious patterns detected; the file is a standard Babel decorators helper implementing ES decorator semantics.
- `helpers/applyDecs2305.js` (safe): No malicious patterns detected; this is a standard Babel helper for decorator semantics with no network, filesystem, process, or obfuscated code.
- `helpers/applyDecs2311.js` (safe): This is a Babel helper for decorator metadata (applyDecs2311) with no malicious patterns, network calls, environment access, or dynamic code execution.
- `helpers/arrayLikeToArray.js` (safe): This is a benign Babel helper function that converts array-like objects to arrays with no malicious patterns detected.
- `helpers/arrayWithHoles.js` (safe): No malicious patterns detected
- `helpers/arrayWithoutHoles.js` (safe): No malicious patterns detected
- `helpers/assertClassBrand.js` (safe): No malicious patterns detected
- `helpers/assertThisInitialized.js` (safe): No malicious patterns detected; the file is a standard Babel helper that validates `this` initialization.
- `helpers/asyncGeneratorDelegate.js` (safe): No malicious patterns detected; this is a standard Babel helper for async generator delegation.
- `helpers/asyncIterator.js` (safe): No malicious patterns detected; this is a standard Babel helper for async iteration with no network, filesystem, process, or dynamic code execution activity.
- `helpers/asyncToGenerator.js` (safe): No malicious patterns detected; this is the standard Babel asyncToGenerator helper for converting async functions to generator-based promise chains.
- `helpers/awaitAsyncGenerator.js` (safe): No malicious patterns detected; the file is a simple Babel helper that wraps a value in an OverloadYield object without any dangerous operations.
- `helpers/callSuper.js` (safe): This is a standard Babel helper function for calling super constructors, with no malicious patterns detected.
- `helpers/checkInRHS.js` (safe): No malicious patterns detected
- `helpers/checkPrivateRedeclaration.js` (safe): No malicious patterns detected; the code is a standard Babel helper for private field redeclaration checks with no network, filesystem, process, or dynamic execution behavior.
- `helpers/classApplyDescriptorDestructureSet.js` (safe): No malicious patterns detected; the file is a standard Babel helper for private field destructuring assignment.
- `helpers/classApplyDescriptorGet.js` (safe): No malicious patterns detected
- `helpers/classApplyDescriptorSet.js` (safe): No malicious patterns detected; the code is a standard Babel helper for setting private class fields with proper validation and no external interactions.
- `helpers/classCallCheck.js` (safe): No malicious patterns detected
- `helpers/classCheckPrivateStaticAccess.js` (safe): No malicious patterns detected
- `helpers/classCheckPrivateStaticFieldDescriptor.js` (safe): No malicious patterns detected; the file is a benign Babel helper function for checking private static field declarations.
- `helpers/classExtractFieldDescriptor.js` (safe): No malicious patterns detected; the file is a simple Babel helper that delegates to another local module.
- `helpers/classNameTDZError.js` (safe): No malicious patterns detected
- `helpers/classPrivateFieldDestructureSet.js` (safe): No malicious patterns detected
- `helpers/classPrivateFieldGet.js` (safe): No malicious patterns detected; this is a standard Babel helper for accessing private class fields.
- `helpers/classPrivateFieldGet2.js` (safe): No malicious patterns detected; this is a standard Babel helper for private field access with no external, network, filesystem, or process activity.
- `helpers/classPrivateFieldInitSpec.js` (safe): This is a standard Babel helper for private field initialization with no malicious patterns detected.
- `helpers/classPrivateFieldLooseBase.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for private field access checks.
- `helpers/classPrivateFieldLooseKey.js` (safe): No malicious patterns detected in this small utility module that generates unique private field key names.
- `helpers/classPrivateFieldSet.js` (safe): No malicious patterns detected; this is a standard Babel helper for setting private class fields.
- `helpers/classPrivateFieldSet2.js` (safe): No malicious patterns detected; the helper performs a standard private field set using class brand assertion without any external calls, dynamic execution, or I/O.
- `helpers/classPrivateGetter.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for private getter access.
- `helpers/classPrivateMethodGet.js` (safe): No malicious patterns detected; this is a standard Babel helper for private method access.
- `helpers/classPrivateMethodInitSpec.js` (safe): No malicious patterns detected
- `helpers/classPrivateMethodSet.js` (safe): The file contains a standard Babel helper that throws a TypeError when attempting to reassign a private method; no malicious patterns detected.
- `helpers/classPrivateSetter.js` (safe): No malicious patterns detected
- `helpers/classStaticPrivateFieldDestructureSet.js` (safe): No malicious patterns detected; this is a standard Babel helper for private static field destructuring assignment.
- `helpers/classStaticPrivateFieldSpecGet.js` (safe): No malicious patterns detected; this is a standard Babel helper for private static field access with no network, filesystem, process, or dynamic code execution behavior.
- `helpers/classStaticPrivateFieldSpecSet.js` (safe): No malicious patterns detected
- `helpers/classStaticPrivateMethodGet.js` (safe): No malicious patterns detected; the file is a standard Babel helper for accessing static private methods.
- `helpers/classStaticPrivateMethodSet.js` (safe): No malicious patterns detected in this Babel runtime helper that only throws a TypeError for read-only static private field assignments.
- `helpers/construct.js` (safe): No malicious patterns detected; this is a standard Babel helper for Reflect.construct fallback.
- `helpers/createClass.js` (safe): No malicious patterns detected; the code is a standard Babel helper for defining class properties.
- `helpers/createForOfIteratorHelper.js` (safe): No malicious patterns detected; this is a standard Babel transpilation helper for for-of iteration.
- `helpers/createForOfIteratorHelperLoose.js` (safe): No malicious patterns detected; the file is a standard Babel helper for loose for-of iteration with no network, filesystem, process, or dynamic code execution behavior.
- `helpers/createSuper.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for creating superclass constructors.
- `helpers/decorate.js` (safe): This is a standard Babel helper for JavaScript decorator transforms with no malicious patterns, network calls, credential access, or dynamic code execution.
- `helpers/defaults.js` (safe): No malicious patterns detected; the code is a standard utility for copying default properties, with no network, filesystem, or process activity.
- `helpers/defineAccessor.js` (safe): No malicious patterns detected; the code is a standard Babel helper for defining object properties.
- `helpers/defineEnumerableProperties.js` (safe): This is a standard Babel helper function that defines enumerable properties; it contains no malicious patterns, network activity, credential access, dynamic code execution, or lifecycle scripts.
- `helpers/defineProperty.js` (safe): No malicious patterns detected
- `helpers/dispose.js` (safe): No malicious patterns detected; the code is a standard Babel helper implementing the explicit resource management dispose protocol with SuppressedError support, containing no network, filesystem, process, or dynamic execution behavior.
- `helpers/esm/AwaitValue.js` (safe): No malicious patterns detected
- `helpers/esm/OverloadYield.js` (safe): No malicious patterns detected; the file defines a simple constructor function and exports it as default.
- `helpers/esm/applyDecoratedDescriptor.js` (safe): No malicious patterns detected
- `helpers/esm/applyDecs.js` (safe): No malicious patterns detected; the code is a standard Babel helper for implementing decorators and metadata, with no network, filesystem, process execution, or obfuscated behavior.
- `helpers/esm/applyDecs2203.js` (safe): This is a standard Babel helper module implementing the decorators proposal (applyDecs2203) with no network, filesystem, process, or dynamic code execution patterns.
- `helpers/esm/applyDecs2203R.js` (safe): This is a legitimate Babel helper for decorator transpilation with no malicious patterns detected.
- `helpers/esm/applyDecs2301.js` (safe): No malicious patterns detected
- `helpers/esm/applyDecs2305.js` (safe): This is a legitimate Babel helper implementing the ES decorators proposal (applyDecs2305) with no malicious patterns, network access, file system manipulation, or obfuscated code.
- `helpers/esm/applyDecs2311.js` (safe): No malicious patterns detected
- `helpers/esm/arrayLikeToArray.js` (safe): No malicious patterns detected
- `helpers/esm/arrayWithHoles.js` (safe): No malicious patterns detected
- `helpers/esm/arrayWithoutHoles.js` (safe): No malicious patterns detected
- `helpers/esm/assertClassBrand.js` (safe): No malicious patterns detected
- `helpers/esm/assertThisInitialized.js` (safe): No malicious patterns detected
- `helpers/esm/asyncGeneratorDelegate.js` (safe): No malicious patterns detected; this is a standard Babel helper for async generator delegation.
- `helpers/esm/asyncIterator.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for async iterator support with no network, filesystem, or code execution behavior.
- `helpers/esm/asyncToGenerator.js` (safe): No malicious patterns detected; the code is a standard Babel async-to-generator helper with no network, filesystem, process, or obfuscation activity.
- `helpers/esm/awaitAsyncGenerator.js` (safe): The file is a trivial Babel helper that wraps a value in an OverloadYield object with no malicious behavior or side effects.
- `helpers/esm/callSuper.js` (safe): No malicious patterns detected; this is a standard Babel transpilation helper for calling super constructors with no external network, filesystem, or code execution activity.
- `helpers/esm/checkInRHS.js` (safe): No malicious patterns detected; the file is a standard Babel helper function for validating the right-hand side of 'in' operators.
- `helpers/esm/checkPrivateRedeclaration.js` (safe): No malicious patterns detected
- `helpers/esm/classApplyDescriptorDestructureSet.js` (safe): No malicious patterns detected
- `helpers/esm/classApplyDescriptorGet.js` (safe): No malicious patterns detected; the code only provides a simple helper for accessing class descriptor values via getters or direct values.
- `helpers/esm/classApplyDescriptorSet.js` (safe): This is a standard Babel helper function for applying values to class private fields with no malicious patterns detected.
- `helpers/esm/classCallCheck.js` (safe): No malicious patterns detected
- `helpers/esm/classCheckPrivateStaticAccess.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/esm/classCheckPrivateStaticFieldDescriptor.js` (safe): No malicious patterns detected; the code is a simple helper function that throws a TypeError when a private static field is accessed before its declaration.
- `helpers/esm/classExtractFieldDescriptor.js` (safe): No malicious patterns detected
- `helpers/esm/classNameTDZError.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateFieldDestructureSet.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateFieldGet.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for private class field access with no suspicious behavior.
- `helpers/esm/classPrivateFieldGet2.js` (safe): No malicious patterns detected; the code is a legitimate Babel helper for private field access with no suspicious behavior.
- `helpers/esm/classPrivateFieldInitSpec.js` (safe): This is a standard Babel helper for initializing private class fields; it performs no network, filesystem, or process operations and contains no malicious patterns.
- `helpers/esm/classPrivateFieldLooseBase.js` (safe): This is a standard Babel helper function for private field access with no malicious patterns.
- `helpers/esm/classPrivateFieldLooseKey.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateFieldSet.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateFieldSet2.js` (safe): This is a standard Babel transpilation helper for setting private class fields, with no malicious patterns or security concerns.
- `helpers/esm/classPrivateGetter.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateMethodGet.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateMethodInitSpec.js` (safe): No malicious patterns detected
- `helpers/esm/classPrivateMethodSet.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/esm/classPrivateSetter.js` (safe): No malicious patterns detected
- `helpers/esm/classStaticPrivateFieldDestructureSet.js` (safe): No malicious patterns detected
- `helpers/esm/classStaticPrivateFieldSpecGet.js` (safe): No malicious patterns detected; this is a standard Babel helper for accessing private static fields.
- `helpers/esm/classStaticPrivateFieldSpecSet.js` (safe): No malicious patterns detected in this Babel helper module; it is a straightforward static private field setter with no network, filesystem, or code execution behavior.
- `helpers/esm/classStaticPrivateMethodGet.js` (safe): No malicious patterns detected; the file is a small helper that asserts a class brand and returns a method reference.
- `helpers/esm/classStaticPrivateMethodSet.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/esm/construct.js` (safe): No malicious patterns detected
- `helpers/esm/createClass.js` (safe): No malicious patterns detected
- `helpers/esm/createForOfIteratorHelper.js` (safe): The file is a standard Babel transpilation helper for iterating over iterables and contains no malicious patterns.
- `helpers/esm/createForOfIteratorHelperLoose.js` (safe): No malicious patterns detected; this is a standard Babel helper for iterating objects safely.
- `helpers/esm/createSuper.js` (safe): The code is a standard Babel helper for extending ES6 classes, using only safe reflection and prototype utilities with no malicious patterns.
- `helpers/esm/decorate.js` (safe): No malicious patterns detected; the code is a standard Babel helper for implementing the JavaScript decorators proposal.
- `helpers/esm/defaults.js` (safe): No malicious patterns detected; the code is a standard utility function for copying configurable own properties from a source object to a target object.
- `helpers/esm/defineAccessor.js` (safe): This is a standard Babel helper function for defining object accessors; no malicious patterns detected.
- `helpers/esm/defineEnumerableProperties.js` (safe): No malicious patterns detected; this is a standard Babel helper function for defining enumerable properties.
- `helpers/esm/defineProperty.js` (safe): Legitimate Babel helper for defining object properties with no malicious patterns detected
- `helpers/esm/dispose.js` (safe): No malicious patterns detected; the code is a standard polyfill/polyfill-like implementation for resource disposal (using SuppressedError) with no network, filesystem, process, or dynamic code execution behavior.
- `helpers/esm/extends.js` (safe): No malicious patterns detected
- `helpers/esm/get.js` (safe): This is a standard Babel helper for Reflect.get with super property fallback, containing no malicious patterns or suspicious behavior.
- `helpers/esm/getPrototypeOf.js` (safe): No malicious patterns detected; this is a standard Babel helper for getPrototypeOf with no network, filesystem, process, or dynamic execution behavior.
- `helpers/esm/identity.js` (safe): No malicious patterns detected
- `helpers/esm/importDeferProxy.js` (safe): No malicious patterns detected
- `helpers/esm/inherits.js` (safe): No malicious patterns detected; this is a standard Babel helper for prototypal inheritance.
- `helpers/esm/inheritsLoose.js` (safe): No malicious patterns detected
- `helpers/esm/initializerDefineProperty.js` (safe): No malicious patterns detected
- `helpers/esm/initializerWarningHelper.js` (safe): No malicious patterns detected
- `helpers/esm/instanceof.js` (safe): No malicious patterns detected; the code is a standard Babel helper implementing an instanceof polyfill with no network, filesystem, process, or dynamic execution behavior.
- `helpers/esm/interopRequireDefault.js` (safe): No malicious patterns detected
- `helpers/esm/interopRequireWildcard.js` (safe): This is a standard Babel ESM interop helper that only performs module namespace wrapping and does not exhibit any malicious patterns.
- `helpers/esm/isNativeFunction.js` (safe): No malicious patterns detected
- `helpers/esm/isNativeReflectConstruct.js` (safe): This is a standard Babel helper for detecting native Reflect.construct support with no malicious patterns, network calls, filesystem access, or dynamic code execution.
- `helpers/esm/iterableToArray.js` (safe): No malicious patterns detected; the code is a standard Babel helper that safely converts iterables to arrays without side effects or external access.
- `helpers/esm/iterableToArrayLimit.js` (safe): No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays.
- `helpers/esm/jsx.js` (safe): No malicious patterns detected; the code is a standard React element creation helper with no network, filesystem, process, or obfuscation concerns.
- `helpers/esm/maybeArrayLike.js` (safe): No malicious patterns detected; this is a benign Babel helper for array-like handling.
- `helpers/esm/newArrowCheck.js` (safe): No malicious patterns detected
- `helpers/esm/nonIterableRest.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/esm/nonIterableSpread.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/esm/nullishReceiverError.js` (safe): No malicious patterns detected; the file only defines a helper that throws a TypeError.
- `helpers/esm/objectDestructuringEmpty.js` (safe): No malicious patterns detected
- `helpers/esm/objectSpread.js` (safe): No malicious patterns detected; the file is a standard Babel helper for object spread compatibility.
- `helpers/esm/objectSpread2.js` (safe): No malicious patterns detected; this is a standard Babel helper for object spread syntax with no network, filesystem, or dynamic code execution.
- `helpers/esm/objectWithoutProperties.js` (safe): No malicious patterns detected
- `helpers/esm/objectWithoutPropertiesLoose.js` (safe): No malicious patterns detected
- `helpers/esm/possibleConstructorReturn.js` (safe): No malicious patterns detected
- `helpers/esm/readOnlyError.js` (safe): The file contains a trivial Babel-style helper that throws a TypeError for read-only property assignments, with no network, filesystem, process, credential, or obfuscation concerns.
- `helpers/esm/regenerator.js` (safe): This is a standard Babel regenerator-runtime helper that contains no malicious patterns, network activity, environment access, or dynamic code execution.
- `helpers/esm/regeneratorAsync.js` (safe): No malicious patterns detected
- `helpers/esm/regeneratorAsyncGen.js` (safe): No malicious patterns detected; the file is a small, standard ESM wrapper for regenerator async generators and only imports local helper modules.
- `helpers/esm/regeneratorAsyncIterator.js` (safe): No malicious patterns detected; the file is a standard Babel regenerator runtime helper implementing async iterator support without network, filesystem, process, or dynamic code execution behavior.
- `helpers/esm/regeneratorDefine.js` (safe): No malicious patterns detected; the code is a standard regenerator runtime helper for defining properties.
- `helpers/esm/regeneratorKeys.js` (safe): The code is a standard Babel/regenerator helper that iterates over object keys; no malicious patterns, network, filesystem, or dynamic execution concerns were found.
- `helpers/esm/regeneratorRuntime.js` (safe): No malicious patterns detected
- `helpers/esm/regeneratorValues.js` (safe): This is a standard Babel helper for iterating regenerator values with no malicious patterns, network activity, or suspicious behavior.
- `helpers/esm/set.js` (safe): No malicious patterns detected
- `helpers/esm/setFunctionName.js` (safe): No malicious patterns detected; the code is a straightforward utility for setting function names with safe property definition and error handling.
- `helpers/esm/setPrototypeOf.js` (safe): No malicious patterns detected; this is a standard Babel helper for setting an object's prototype.
- `helpers/esm/skipFirstGeneratorNext.js` (safe): No malicious patterns detected; the code is a standard helper for skipping the first yield of a generator function.
- `helpers/esm/slicedToArray.js` (safe): No malicious patterns detected
- `helpers/esm/superPropBase.js` (safe): No malicious patterns detected; the file is a standard Babel helper for accessing superclass properties.
- `helpers/esm/superPropGet.js` (safe): No malicious patterns detected; the file is a benign Babel helper for accessing superclass properties.
- `helpers/esm/superPropSet.js` (safe): No malicious patterns detected
- `helpers/esm/taggedTemplateLiteral.js` (safe): No malicious patterns detected
- `helpers/esm/taggedTemplateLiteralLoose.js` (safe): No malicious patterns detected
- `helpers/esm/tdz.js` (safe): No malicious patterns detected
- `helpers/esm/temporalRef.js` (safe): No malicious patterns detected
- `helpers/esm/temporalUndefined.js` (safe): No malicious patterns detected
- `helpers/esm/toArray.js` (safe): No malicious patterns detected; the file implements a standard Babel helper for converting iterables to arrays with no suspicious behavior.
- `helpers/esm/toConsumableArray.js` (safe): Cleared by Jev triage; no further analysis needed
- `helpers/esm/toPrimitive.js` (safe): No malicious patterns detected
- `helpers/esm/toPropertyKey.js` (safe): No malicious patterns detected; the code is a standard Babel helper for converting values to property keys.
- `helpers/esm/toSetter.js` (safe): No malicious patterns detected
- `helpers/esm/tsRewriteRelativeImportExtensions.js` (safe): No malicious patterns detected; the code is a benign utility that rewrites TypeScript import extensions to JavaScript equivalents.
- `helpers/esm/typeof.js` (safe): No malicious patterns detected
- `helpers/esm/unsupportedIterableToArray.js` (safe): No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays.
- `helpers/esm/using.js` (safe): No malicious patterns detected; this is a standard Babel helper implementing the TC39 'using' declaration disposal mechanism using Symbol.dispose/Symbol.asyncDispose.
- `helpers/esm/usingCtx.js` (safe): This is a standard Babel/TypeScript helper for transpiling the 'using' declarations proposal (explicit resource management); it contains no malicious patterns such as network access, credential harvesting, obfuscation, or code execution.
- `helpers/esm/wrapAsyncGenerator.js` (safe): No malicious patterns detected; the file is a standard Babel async generator helper with no network, filesystem, process, or eval activity.
- `helpers/esm/wrapNativeSuper.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper implementing _wrapNativeSuper with no network, filesystem, process, or dynamic code execution activity.
- `helpers/esm/wrapRegExp.js` (safe): No malicious patterns detected; this is a legitimate Babel helper for extending RegExp with named groups.
- `helpers/esm/writeOnlyError.js` (safe): The file contains a trivial helper function that throws a TypeError for write-only property access, with no malicious patterns or suspicious behavior detected.
- `helpers/extends.js` (safe): No malicious patterns detected
- `helpers/get.js` (safe): No malicious patterns detected; this is a standard Babel helper for ES6 Reflect.get/super property access with no network, filesystem, or execution risks.
- `helpers/getPrototypeOf.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for getting an object's prototype.
- `helpers/identity.js` (safe): The file contains a simple identity function with standard module exports and no malicious patterns.
- `helpers/importDeferProxy.js` (safe): No malicious patterns detected
- `helpers/inherits.js` (safe): No malicious patterns detected
- `helpers/inheritsLoose.js` (safe): No malicious patterns detected
- `helpers/initializerDefineProperty.js` (safe): This is a standard Babel helper function that safely defines object properties with no malicious patterns.
- `helpers/initializerWarningHelper.js` (safe): This is a standard Babel runtime helper function that only throws an error when decorators are misconfigured; no malicious patterns detected.
- `helpers/instanceof.js` (safe): No malicious patterns detected
- `helpers/interopRequireDefault.js` (safe): No malicious patterns detected
- `helpers/interopRequireWildcard.js` (safe): No malicious patterns detected; this is a standard Babel helper for interopRequireWildcard with no network, filesystem, process, or dynamic execution behavior.
- `helpers/isNativeFunction.js` (safe): The file contains only a standard utility function to detect native functions via Function.prototype.toString, with no malicious patterns, network activity, file access, or code execution.
- `helpers/isNativeReflectConstruct.js` (safe): The code is a standard Babel helper for detecting native Reflect.construct support, with no malicious patterns, network activity, or suspicious behavior.
- `helpers/iterableToArray.js` (safe): No malicious patterns detected
- `helpers/iterableToArrayLimit.js` (safe): No malicious patterns detected; this is a standard Babel helper for safely converting iterables to arrays with length limits.
- `helpers/jsx.js` (safe): This is a standard Babel/React JSX runtime helper that creates React elements; no malicious patterns, network calls, file access, or dynamic code execution were found.
- `helpers/maybeArrayLike.js` (safe): No malicious patterns detected
- `helpers/newArrowCheck.js` (safe): No malicious patterns detected; this is a standard Babel helper for arrow function instantiation checks.

## Version ranges

None of the 2 scanned versions of @babel/runtime are flagged high or critical. The latest scanned version, 8.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 7.29.2 – 8.0.0 (`>=7.29.2 <=8.0.0`): not scanned
- 7.28.4 – 7.28.6 (`>=7.28.4 <=7.28.6`): medium

## Scanned versions

- [7.28.6](https://security.togoder.click/npm/@babel/runtime@7.28.6): medium, 2026-10-06T14:10:43.000Z
- [7.28.4](https://security.togoder.click/npm/@babel/runtime@7.28.4): medium, 2026-10-04T16:01:46.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
