Summary
Togoder Security scanned the npm package @cspotcode/source-map-support@0.8.1 on Oct 4, 2026. An AI review of 4 source files produced 1 critical, 4 medium, 2 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.
Findings 7
Code that runs at install time
NPS-8C60F578BB18
The file executes require('./').install() at the top level. When this file is loaded (e.g., during npm install, postinstall, or as part of package initialization), it immediately invokes an install() function from the package's main entry point. This means arbitrary code execution occurs automatically upon installation or import, with no user consent. The actual behavior of install() cannot be determined from this snippet alone, but the pattern is a common vector for malicious packages that perform actions like credential harvesting, backdoor installation, or data exfiltration during install.
Runtime module hooking
NPS-9247F0E6F69D
The file calls require('./').install({ hookRequire: true }), which installs a require hook at import time. This intercepts all subsequent require() calls in the process and allows the package to transform or wrap module loading. While this is a legitimate technique used by libraries like 'module-alias', 'require-in-the-middle', and 'rewiremock', it is a powerful capability that can be abused to inject malicious code into every module loaded, hide other malicious behavior, or exfiltrate module sources. It runs immediately when this file is imported (side-effect on import), which is a common behavior for npm postinstall or import-time payloads.
synchronous file reads and browser XHR based on stack-derived paths
NPS-48DF82430F95
retrieveFile and retrieveSourceMapURL read file contents synchronously based on file paths extracted from stack traces. In browser environments it performs synchronous XMLHttpRequest to arbitrary URLs derived from stack frames. While the paths come from the runtime stack rather than direct user input, this behavior fetches and caches file contents (including source maps) and can be abused if an attacker can craft stack frames or sourceMappingURL comments that point to sensitive local files or attacker-controlled servers.
monkey-patching of core Node.js runtime
NPS-9A56F966588A
The library overrides several Node.js built-in mechanisms at import/install time: Error.prepareStackTrace, process.emit, and Module._resolveFilename. This allows it to intercept uncaught exceptions, stack traces, and module resolution globally for the entire process. While intended for source-map support, this level of runtime modification can mask or redirect error handling and module resolution behavior, which is a significant privilege escalation surface if the package were compromised or if its behavior was unexpected.
dynamic module resolution redirect
NPS-51F6E3AB0346
The install() function monkey-patches Module._resolveFilename to redirect requests for 'source-map-support' and 'source-map-support/register' to its own bundle. It calls require.resolve(requestRedirect) dynamically and invokes user-supplied callbacks (onConflictingLibraryRedirectArr). This can silently change which module another part of the application loads, potentially loading attacker-controlled code if an attacker can influence the module path or the callback list.
install-time top-level side effects
NPS-CD4F2E4891CC
Merely requiring this module executes top-level code that initializes shared state and registers internal retrieve handlers. exports.install() further installs global error and process hooks, optionally shimming uncaughtException handling and terminating the process. These are expected for the package's purpose but constitute import/install-time code execution that modifies global process behavior.
dynamic require to bypass bundlers
NPS-B877F2D9F453
The dynamicRequire helper calls mod.require(request) with computed request strings ('module', 'worker_threads') to avoid static analysis by bundlers. This is a legitimate technique, but it is also a pattern frequently used by malicious packages to hide dynamic module loading from security scanners.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| register.js | critical | The file unconditionally executes an install() function at import time, enabling arbitrary code execution during package installation, which is a critical security concern. |
| register-hook-require.js | medium | This file installs a require hook at import time, which is a legitimate but powerful monkey-patching technique that can be abused to intercept and modify module loading; the referenced implementation should be inspected to confirm the hook is benign. |
| source-map-support.js | medium | This is the legitimate source-map-support package and contains no clear data exfiltration or backdoor, but it does perform extensive global monkey-patching of Node.js internals, dynamic module resolution redirection, and synchronous file/URL reads derived from stack traces that warrant security review in sensitive environments. |
| browser-source-map-support.js | safe | No malicious patterns detected |
Frequently asked questions
Is @cspotcode/source-map-support safe to use?
@cspotcode/source-map-support@0.8.1 has 1 critical, 4 medium, 2 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.
Does @cspotcode/source-map-support contain malware?
The latest scan of @cspotcode/source-map-support (0.8.1) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.
How was @cspotcode/source-map-support checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @cspotcode/source-map-support together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @cspotcode/source-map-support@0.8.1, cost nothing.