Summary
Togoder Security scanned the npm package @emnapi/runtime@1.11.3 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 11 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 12
Dynamic code execution
NPS-E87F8837B095
The code attempts to dynamically construct and execute functions using new Function. Specifically, new Function('return this')() is used to obtain the global object, and new Function is checked for availability. While this is a known pattern for obtaining the global context (often used in bundlers), the use of new Function can be abused for code execution if inputs are controlled. In this case, the function is called without arguments to return the global object, which is a common benign pattern, but it still constitutes dynamic code execution.
Dynamic code execution
NPS-D7D6840882E5
The code uses new Function() (via a supportNewFunction check and new Function('return this')()) to dynamically create and execute code. While these specific uses are for feature detection and retrieving the global object, the presence of dynamic code execution in a library can be a security concern if not properly controlled.
Dynamic module loading
NPS-B02A23D4E664
The code attempts to require modules like worker_threads and buffer at runtime using a _require function that may call __non_webpack_require__ or require. This dynamic loading could potentially be exploited if the module names were user-controllable, but here they are hardcoded.
Dynamic code execution
NPS-8F3084356FA4
The code uses new Function() to obtain a reference to the global object and to test support for Function constructors. While this is a common pattern in bundled libraries, it represents dynamic code execution that could be exploited if the input is attacker-controlled. In this file, the usage is hardcoded and not user-controlled.
Conditional require of modules
NPS-837B7B78DD8E
The code conditionally requires 'worker_threads' and 'buffer' modules using a dynamically determined require function. This could potentially load unintended modules if the environment is manipulated, but the module names are hardcoded.
Use of setImmediate and MessageChannel
NPS-0BB01898FAD4
The code uses setImmediate and MessageChannel for scheduling tasks. These are standard APIs but could be used for timing attacks or to bypass certain security controls in specific contexts.
Process manipulation
NPS-487970115CEB
The code accesses process._fatalException and process.exit, which can terminate the Node.js process. This behavior is part of error handling but could be abused if an attacker controls the error flow.
FinalizationRegistry usage
NPS-12417E3A8FE5
The code uses FinalizationRegistry to manage weak references. While this is a legitimate feature, it can be complex and may lead to unexpected behavior if not properly handled, but it is not inherently malicious.
Environment access and fallback mechanisms
NPS-F856469AE66B
The code includes logic to access require and fallback to __non_webpack_require__ and global to load modules like worker_threads and buffer. While these are standard for environment detection and polyfilling, they could be used to load arbitrary modules if the environment is manipulated. In this context, they are used to conditionally load built-in modules, which is expected for a library that needs to work in different environments.
Dynamic code execution
NPS-FD69FD114515
Uses new Function() (and new Function('return this')()) to obtain a reference to the global object. While new Function is used here only for a benign runtime feature-detection/global-access purpose, dynamic code generation via the Function constructor is a pattern commonly abused by malicious packages and can be a code-injection vector if input ever flows into it. Its presence in third-party code warrants attention.
Dynamic module loading
NPS-98FA2431AF9D
The _require logic conditionally loads modules by name ('worker_threads', 'buffer') and references __non_webpack_require__/require. This is module loading with runtime-computed behavior rather than static imports. It is used for legitimate Node-API polyfill purposes, but dynamic require is a red-flag pattern that could be repurposed for loading external code.
Environment/process interaction
NPS-7C248E1B0560
Reads process.execArgv, calls process.emitWarning, process._fatalException, process.exit(1), and registers process.once('beforeExit', ...). These interact with the Node process lifecycle and can terminate the process. Used here for Node-API exception handling semantics, but process termination and internal (underscore-prefixed) process API use is sensitive.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/emnapi.esm-bundler.js | medium | The code contains dynamic code execution and dynamic module loading patterns, but these are used for legitimate feature detection and environment compatibility, not malicious purposes. |
| dist/emnapi.iife.js | medium | The file contains standard Node.js addon API (Node-API) implementation with some dynamic code execution and conditional module loading, but no clearly malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected. |
| dist/emnapi.min.mjs | medium | The code contains benign dynamic code execution and environment detection patterns typical of a Node-API binding library, but these patterns could be misused if the source is tampered with. |
| dist/emnapi.mjs | medium | The file is the emnapi (Node-API for WebAssembly) runtime shim and contains no clear exfiltration, credential harvesting, shell spawning, or backdoor logic, but does use dynamic code generation (new Function), dynamic require, and process-level hooks that are low-risk in context yet noteworthy red-flag patterns in third-party code. |
| dist/emnapi.cjs.js | safe | No malicious patterns detected; the code is a legitimate Node-API/eCosystem helper library with no data exfiltration, credential harvesting, obfuscation, backdoors, or suspicious runtime behavior. |
| dist/emnapi.js | safe | No malicious patterns detected; the code is a legitimate Node-API runtime implementation with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| index.js | safe | Standard conditional module export based on NODE_ENV; no malicious patterns detected |
Affected version ranges
None of the 3 scanned versions of @emnapi/runtime are flagged high or critical. The latest scanned version, 1.11.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.0.0-alpha.3 | Not scanned | 1 | 2.0.0-alpha.3 | |
| 1.10.0 – 1.11.3 | Needs review | 3 | >=1.10.0 <=1.11.3 | Dynamic code execution |
| 1.4.5 – 1.7.1 | Not scanned | 2 | >=1.4.5 <=1.7.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @emnapi/runtime
Frequently asked questions
Is @emnapi/runtime safe to use?
No confirmed malware was found in @emnapi/runtime@1.11.3, but the review flagged 1 medium, 11 low severity findings for risky patterns worth checking before you rely on it.
Does @emnapi/runtime contain malware?
No malware was identified in @emnapi/runtime@1.11.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @emnapi/runtime checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @emnapi/runtime together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @emnapi/runtime@1.11.3, cost nothing.