Togoder security

npm package security report

@cspotcode/source-map-support@0.8.1 security report

Critical: dangerous or likely malicious code found.

Critical risk Version 0.8.1 Files reviewed 4 Size 84.4 KB Scanned

Summary

Togoder Security scanned the npm package @cspotcode/source-map-support@0.8.1 on Oct 4, 2026. An AI review of 4 source files produced 1 critical, 4 medium, 2 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

1
critical
0
high
4
medium
2
low

Findings 7

critical

Code that runs at install time

NPS-8C60F578BB18

The file executes require('./').install() at the top level. When this file is loaded (e.g., during npm install, postinstall, or as part of package initialization), it immediately invokes an install() function from the package's main entry point. This means arbitrary code execution occurs automatically upon installation or import, with no user consent. The actual behavior of install() cannot be determined from this snippet alone, but the pattern is a common vector for malicious packages that perform actions like credential harvesting, backdoor installation, or data exfiltration during install.

register.js:1
medium

Runtime module hooking

NPS-9247F0E6F69D

The file calls require('./').install({ hookRequire: true }), which installs a require hook at import time. This intercepts all subsequent require() calls in the process and allows the package to transform or wrap module loading. While this is a legitimate technique used by libraries like 'module-alias', 'require-in-the-middle', and 'rewiremock', it is a powerful capability that can be abused to inject malicious code into every module loaded, hide other malicious behavior, or exfiltrate module sources. It runs immediately when this file is imported (side-effect on import), which is a common behavior for npm postinstall or import-time payloads.

register-hook-require.js:1
medium

synchronous file reads and browser XHR based on stack-derived paths

NPS-48DF82430F95

retrieveFile and retrieveSourceMapURL read file contents synchronously based on file paths extracted from stack traces. In browser environments it performs synchronous XMLHttpRequest to arbitrary URLs derived from stack frames. While the paths come from the runtime stack rather than direct user input, this behavior fetches and caches file contents (including source maps) and can be abused if an attacker can craft stack frames or sourceMappingURL comments that point to sensitive local files or attacker-controlled servers.

source-map-support.js:212
medium

monkey-patching of core Node.js runtime

NPS-9A56F966588A

The library overrides several Node.js built-in mechanisms at import/install time: Error.prepareStackTrace, process.emit, and Module._resolveFilename. This allows it to intercept uncaught exceptions, stack traces, and module resolution globally for the entire process. While intended for source-map support, this level of runtime modification can mask or redirect error handling and module resolution behavior, which is a significant privilege escalation surface if the package were compromised or if its behavior was unexpected.

source-map-support.js:639
medium

dynamic module resolution redirect

NPS-51F6E3AB0346

The install() function monkey-patches Module._resolveFilename to redirect requests for 'source-map-support' and 'source-map-support/register' to its own bundle. It calls require.resolve(requestRedirect) dynamically and invokes user-supplied callbacks (onConflictingLibraryRedirectArr). This can silently change which module another part of the application loads, potentially loading attacker-controlled code if an attacker can influence the module path or the callback list.

source-map-support.js:639
low

install-time top-level side effects

NPS-CD4F2E4891CC

Merely requiring this module executes top-level code that initializes shared state and registers internal retrieve handlers. exports.install() further installs global error and process hooks, optionally shimming uncaughtException handling and terminating the process. These are expected for the package's purpose but constitute import/install-time code execution that modifies global process behavior.

source-map-support.js:1
low

dynamic require to bypass bundlers

NPS-B877F2D9F453

The dynamicRequire helper calls mod.require(request) with computed request strings ('module', 'worker_threads') to avoid static analysis by bundlers. This is a legitimate technique, but it is also a pattern frequently used by malicious packages to hide dynamic module loading from security scanners.

source-map-support.js:20

Files reviewed

FileVerdictWhat the reviewer saw
register.js critical The file unconditionally executes an install() function at import time, enabling arbitrary code execution during package installation, which is a critical security concern.
register-hook-require.js medium This file installs a require hook at import time, which is a legitimate but powerful monkey-patching technique that can be abused to intercept and modify module loading; the referenced implementation should be inspected to confirm the hook is benign.
source-map-support.js medium This is the legitimate source-map-support package and contains no clear data exfiltration or backdoor, but it does perform extensive global monkey-patching of Node.js internals, dynamic module resolution redirection, and synchronous file/URL reads derived from stack traces that warrant security review in sensitive environments.
browser-source-map-support.js safe No malicious patterns detected

Frequently asked questions

Is @cspotcode/source-map-support safe to use?

@cspotcode/source-map-support@0.8.1 has 1 critical, 4 medium, 2 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.

Does @cspotcode/source-map-support contain malware?

The latest scan of @cspotcode/source-map-support (0.8.1) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.

How was @cspotcode/source-map-support checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @cspotcode/source-map-support together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @cspotcode/source-map-support@0.8.1, cost nothing.

Related security reports