Togoder security

npm package security report

@emnapi/runtime@1.11.3 security report

Risky patterns found that deserve a look.

Needs review Version 1.11.3 Files reviewed 7 Size 278.6 KB Scanned

Summary

Togoder Security scanned the npm package @emnapi/runtime@1.11.3 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 11 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
11
low

Findings 12

medium

Dynamic code execution

NPS-E87F8837B095

The code attempts to dynamically construct and execute functions using new Function. Specifically, new Function('return this')() is used to obtain the global object, and new Function is checked for availability. While this is a known pattern for obtaining the global context (often used in bundlers), the use of new Function can be abused for code execution if inputs are controlled. In this case, the function is called without arguments to return the global object, which is a common benign pattern, but it still constitutes dynamic code execution.

dist/emnapi.min.mjs:1
low

Dynamic code execution

NPS-D7D6840882E5

The code uses new Function() (via a supportNewFunction check and new Function('return this')()) to dynamically create and execute code. While these specific uses are for feature detection and retrieving the global object, the presence of dynamic code execution in a library can be a security concern if not properly controlled.

dist/emnapi.esm-bundler.js
low

Dynamic module loading

NPS-B02A23D4E664

The code attempts to require modules like worker_threads and buffer at runtime using a _require function that may call __non_webpack_require__ or require. This dynamic loading could potentially be exploited if the module names were user-controllable, but here they are hardcoded.

dist/emnapi.esm-bundler.js
low

Dynamic code execution

NPS-8F3084356FA4

The code uses new Function() to obtain a reference to the global object and to test support for Function constructors. While this is a common pattern in bundled libraries, it represents dynamic code execution that could be exploited if the input is attacker-controlled. In this file, the usage is hardcoded and not user-controlled.

dist/emnapi.iife.js:70
low

Conditional require of modules

NPS-837B7B78DD8E

The code conditionally requires 'worker_threads' and 'buffer' modules using a dynamically determined require function. This could potentially load unintended modules if the environment is manipulated, but the module names are hardcoded.

dist/emnapi.iife.js:160
low

Use of setImmediate and MessageChannel

NPS-0BB01898FAD4

The code uses setImmediate and MessageChannel for scheduling tasks. These are standard APIs but could be used for timing attacks or to bypass certain security controls in specific contexts.

dist/emnapi.iife.js:170
low

Process manipulation

NPS-487970115CEB

The code accesses process._fatalException and process.exit, which can terminate the Node.js process. This behavior is part of error handling but could be abused if an attacker controls the error flow.

dist/emnapi.iife.js:460
low

FinalizationRegistry usage

NPS-12417E3A8FE5

The code uses FinalizationRegistry to manage weak references. While this is a legitimate feature, it can be complex and may lead to unexpected behavior if not properly handled, but it is not inherently malicious.

dist/emnapi.iife.js:540
low

Environment access and fallback mechanisms

NPS-F856469AE66B

The code includes logic to access require and fallback to __non_webpack_require__ and global to load modules like worker_threads and buffer. While these are standard for environment detection and polyfilling, they could be used to load arbitrary modules if the environment is manipulated. In this context, they are used to conditionally load built-in modules, which is expected for a library that needs to work in different environments.

dist/emnapi.min.mjs:1
low

Dynamic code execution

NPS-FD69FD114515

Uses new Function() (and new Function('return this')()) to obtain a reference to the global object. While new Function is used here only for a benign runtime feature-detection/global-access purpose, dynamic code generation via the Function constructor is a pattern commonly abused by malicious packages and can be a code-injection vector if input ever flows into it. Its presence in third-party code warrants attention.

dist/emnapi.mjs:24
low

Dynamic module loading

NPS-98FA2431AF9D

The _require logic conditionally loads modules by name ('worker_threads', 'buffer') and references __non_webpack_require__/require. This is module loading with runtime-computed behavior rather than static imports. It is used for legitimate Node-API polyfill purposes, but dynamic require is a red-flag pattern that could be repurposed for loading external code.

dist/emnapi.mjs:111
low

Environment/process interaction

NPS-7C248E1B0560

Reads process.execArgv, calls process.emitWarning, process._fatalException, process.exit(1), and registers process.once('beforeExit', ...). These interact with the Node process lifecycle and can terminate the process. Used here for Node-API exception handling semantics, but process termination and internal (underscore-prefixed) process API use is sensitive.

dist/emnapi.mjs:482

Files reviewed

FileVerdictWhat the reviewer saw
dist/emnapi.esm-bundler.js medium The code contains dynamic code execution and dynamic module loading patterns, but these are used for legitimate feature detection and environment compatibility, not malicious purposes.
dist/emnapi.iife.js medium The file contains standard Node.js addon API (Node-API) implementation with some dynamic code execution and conditional module loading, but no clearly malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected.
dist/emnapi.min.mjs medium The code contains benign dynamic code execution and environment detection patterns typical of a Node-API binding library, but these patterns could be misused if the source is tampered with.
dist/emnapi.mjs medium The file is the emnapi (Node-API for WebAssembly) runtime shim and contains no clear exfiltration, credential harvesting, shell spawning, or backdoor logic, but does use dynamic code generation (new Function), dynamic require, and process-level hooks that are low-risk in context yet noteworthy red-flag patterns in third-party code.
dist/emnapi.cjs.js safe No malicious patterns detected; the code is a legitimate Node-API/eCosystem helper library with no data exfiltration, credential harvesting, obfuscation, backdoors, or suspicious runtime behavior.
dist/emnapi.js safe No malicious patterns detected; the code is a legitimate Node-API runtime implementation with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
index.js safe Standard conditional module export based on NODE_ENV; no malicious patterns detected

Affected version ranges

None of the 3 scanned versions of @emnapi/runtime are flagged high or critical. The latest scanned version, 1.11.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.4.52.0.0-alpha.3
VersionsVerdictCountRangeTop findings
2.0.0-alpha.3 Not scanned 1 2.0.0-alpha.3
1.10.0 – 1.11.3 Needs review 3 >=1.10.0 <=1.11.3 Dynamic code execution
1.4.5 – 1.7.1 Not scanned 2 >=1.4.5 <=1.7.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @emnapi/runtime

VersionVerdictFilesScanned
1.11.3 Needs review 7 Oct 6, 2026
1.11.1 Needs review 7 Oct 6, 2026
1.10.0 Needs review 7 Oct 6, 2026

Frequently asked questions

Is @emnapi/runtime safe to use?

No confirmed malware was found in @emnapi/runtime@1.11.3, but the review flagged 1 medium, 11 low severity findings for risky patterns worth checking before you rely on it.

Does @emnapi/runtime contain malware?

No malware was identified in @emnapi/runtime@1.11.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @emnapi/runtime checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @emnapi/runtime together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @emnapi/runtime@1.11.3, cost nothing.

Related security reports