# @cspotcode/source-map-support@0.8.1 security report (npm)

- Verdict: **Critical risk** (risk level: critical)
- Scanned: 2026-10-04T16:06:05.000Z
- Files reviewed: 4
- Findings: 1 critical, 4 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/@cspotcode/source-map-support
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @cspotcode/source-map-support@0.8.1 on Oct 4, 2026. An AI review of 4 source files produced 1 critical, 4 medium, 2 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

## Findings

### [critical] Code that runs at install time

Finding ID: `NPS-8C60F578BB18`

File: `register.js:1`

The file executes require('./').install() at the top level. When this file is loaded (e.g., during npm install, postinstall, or as part of package initialization), it immediately invokes an install() function from the package's main entry point. This means arbitrary code execution occurs automatically upon installation or import, with no user consent. The actual behavior of install() cannot be determined from this snippet alone, but the pattern is a common vector for malicious packages that perform actions like credential harvesting, backdoor installation, or data exfiltration during install.

### [medium] Runtime module hooking

Finding ID: `NPS-9247F0E6F69D`

File: `register-hook-require.js:1`

The file calls require('./').install({ hookRequire: true }), which installs a require hook at import time. This intercepts all subsequent require() calls in the process and allows the package to transform or wrap module loading. While this is a legitimate technique used by libraries like 'module-alias', 'require-in-the-middle', and 'rewiremock', it is a powerful capability that can be abused to inject malicious code into every module loaded, hide other malicious behavior, or exfiltrate module sources. It runs immediately when this file is imported (side-effect on import), which is a common behavior for npm postinstall or import-time payloads.

### [medium] synchronous file reads and browser XHR based on stack-derived paths

Finding ID: `NPS-48DF82430F95`

File: `source-map-support.js:212`

retrieveFile and retrieveSourceMapURL read file contents synchronously based on file paths extracted from stack traces. In browser environments it performs synchronous XMLHttpRequest to arbitrary URLs derived from stack frames. While the paths come from the runtime stack rather than direct user input, this behavior fetches and caches file contents (including source maps) and can be abused if an attacker can craft stack frames or sourceMappingURL comments that point to sensitive local files or attacker-controlled servers.

### [medium] monkey-patching of core Node.js runtime

Finding ID: `NPS-9A56F966588A`

File: `source-map-support.js:639`

The library overrides several Node.js built-in mechanisms at import/install time: Error.prepareStackTrace, process.emit, and Module._resolveFilename. This allows it to intercept uncaught exceptions, stack traces, and module resolution globally for the entire process. While intended for source-map support, this level of runtime modification can mask or redirect error handling and module resolution behavior, which is a significant privilege escalation surface if the package were compromised or if its behavior was unexpected.

### [medium] dynamic module resolution redirect

Finding ID: `NPS-51F6E3AB0346`

File: `source-map-support.js:639`

The install() function monkey-patches Module._resolveFilename to redirect requests for 'source-map-support' and 'source-map-support/register' to its own bundle. It calls require.resolve(requestRedirect) dynamically and invokes user-supplied callbacks (onConflictingLibraryRedirectArr). This can silently change which module another part of the application loads, potentially loading attacker-controlled code if an attacker can influence the module path or the callback list.

### [low] install-time top-level side effects

Finding ID: `NPS-CD4F2E4891CC`

File: `source-map-support.js:1`

Merely requiring this module executes top-level code that initializes shared state and registers internal retrieve handlers. exports.install() further installs global error and process hooks, optionally shimming uncaughtException handling and terminating the process. These are expected for the package's purpose but constitute import/install-time code execution that modifies global process behavior.

### [low] dynamic require to bypass bundlers

Finding ID: `NPS-B877F2D9F453`

File: `source-map-support.js:20`

The dynamicRequire helper calls mod.require(request) with computed request strings ('module', 'worker_threads') to avoid static analysis by bundlers. This is a legitimate technique, but it is also a pattern frequently used by malicious packages to hide dynamic module loading from security scanners.

## Files reviewed

- `register.js` (critical): The file unconditionally executes an install() function at import time, enabling arbitrary code execution during package installation, which is a critical security concern.
- `register-hook-require.js` (medium): This file installs a require hook at import time, which is a legitimate but powerful monkey-patching technique that can be abused to intercept and modify module loading; the referenced implementation should be inspected to confirm the hook is benign.
- `source-map-support.js` (medium): This is the legitimate source-map-support package and contains no clear data exfiltration or backdoor, but it does perform extensive global monkey-patching of Node.js internals, dynamic module resolution redirection, and synchronous file/URL reads derived from stack traces that warrant security review in sensitive environments.
- `browser-source-map-support.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
