# @emnapi/runtime@1.11.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:03.000Z
- Files reviewed: 7
- Findings: 1 medium, 11 low severity findings
- Report: https://security.togoder.click/npm/@emnapi/runtime@1.11.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @emnapi/runtime@1.11.3 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 11 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-E87F8837B095`

File: `dist/emnapi.min.mjs:1`

The code attempts to dynamically construct and execute functions using `new Function`. Specifically, `new Function('return this')()` is used to obtain the global object, and `new Function` is checked for availability. While this is a known pattern for obtaining the global context (often used in bundlers), the use of `new Function` can be abused for code execution if inputs are controlled. In this case, the function is called without arguments to return the global object, which is a common benign pattern, but it still constitutes dynamic code execution.

### [low] Dynamic code execution

Finding ID: `NPS-D7D6840882E5`

File: `dist/emnapi.esm-bundler.js`

The code uses `new Function()` (via a `supportNewFunction` check and `new Function('return this')()`) to dynamically create and execute code. While these specific uses are for feature detection and retrieving the global object, the presence of dynamic code execution in a library can be a security concern if not properly controlled.

### [low] Dynamic module loading

Finding ID: `NPS-B02A23D4E664`

File: `dist/emnapi.esm-bundler.js`

The code attempts to require modules like `worker_threads` and `buffer` at runtime using a `_require` function that may call `__non_webpack_require__` or `require`. This dynamic loading could potentially be exploited if the module names were user-controllable, but here they are hardcoded.

### [low] Dynamic code execution

Finding ID: `NPS-8F3084356FA4`

File: `dist/emnapi.iife.js:70`

The code uses new Function() to obtain a reference to the global object and to test support for Function constructors. While this is a common pattern in bundled libraries, it represents dynamic code execution that could be exploited if the input is attacker-controlled. In this file, the usage is hardcoded and not user-controlled.

### [low] Conditional require of modules

Finding ID: `NPS-837B7B78DD8E`

File: `dist/emnapi.iife.js:160`

The code conditionally requires 'worker_threads' and 'buffer' modules using a dynamically determined require function. This could potentially load unintended modules if the environment is manipulated, but the module names are hardcoded.

### [low] Use of setImmediate and MessageChannel

Finding ID: `NPS-0BB01898FAD4`

File: `dist/emnapi.iife.js:170`

The code uses setImmediate and MessageChannel for scheduling tasks. These are standard APIs but could be used for timing attacks or to bypass certain security controls in specific contexts.

### [low] Process manipulation

Finding ID: `NPS-487970115CEB`

File: `dist/emnapi.iife.js:460`

The code accesses process._fatalException and process.exit, which can terminate the Node.js process. This behavior is part of error handling but could be abused if an attacker controls the error flow.

### [low] FinalizationRegistry usage

Finding ID: `NPS-12417E3A8FE5`

File: `dist/emnapi.iife.js:540`

The code uses FinalizationRegistry to manage weak references. While this is a legitimate feature, it can be complex and may lead to unexpected behavior if not properly handled, but it is not inherently malicious.

### [low] Environment access and fallback mechanisms

Finding ID: `NPS-F856469AE66B`

File: `dist/emnapi.min.mjs:1`

The code includes logic to access `require` and fallback to `__non_webpack_require__` and `global` to load modules like `worker_threads` and `buffer`. While these are standard for environment detection and polyfilling, they could be used to load arbitrary modules if the environment is manipulated. In this context, they are used to conditionally load built-in modules, which is expected for a library that needs to work in different environments.

### [low] Dynamic code execution

Finding ID: `NPS-FD69FD114515`

File: `dist/emnapi.mjs:24`

Uses `new Function()` (and `new Function('return this')()`) to obtain a reference to the global object. While `new Function` is used here only for a benign runtime feature-detection/global-access purpose, dynamic code generation via the Function constructor is a pattern commonly abused by malicious packages and can be a code-injection vector if input ever flows into it. Its presence in third-party code warrants attention.

### [low] Dynamic module loading

Finding ID: `NPS-98FA2431AF9D`

File: `dist/emnapi.mjs:111`

The `_require` logic conditionally loads modules by name ('worker_threads', 'buffer') and references `__non_webpack_require__`/`require`. This is module loading with runtime-computed behavior rather than static imports. It is used for legitimate Node-API polyfill purposes, but dynamic `require` is a red-flag pattern that could be repurposed for loading external code.

### [low] Environment/process interaction

Finding ID: `NPS-7C248E1B0560`

File: `dist/emnapi.mjs:482`

Reads `process.execArgv`, calls `process.emitWarning`, `process._fatalException`, `process.exit(1)`, and registers `process.once('beforeExit', ...)`. These interact with the Node process lifecycle and can terminate the process. Used here for Node-API exception handling semantics, but process termination and internal (underscore-prefixed) process API use is sensitive.

## Files reviewed

- `dist/emnapi.esm-bundler.js` (medium): The code contains dynamic code execution and dynamic module loading patterns, but these are used for legitimate feature detection and environment compatibility, not malicious purposes.
- `dist/emnapi.iife.js` (medium): The file contains standard Node.js addon API (Node-API) implementation with some dynamic code execution and conditional module loading, but no clearly malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected.
- `dist/emnapi.min.mjs` (medium): The code contains benign dynamic code execution and environment detection patterns typical of a Node-API binding library, but these patterns could be misused if the source is tampered with.
- `dist/emnapi.mjs` (medium): The file is the emnapi (Node-API for WebAssembly) runtime shim and contains no clear exfiltration, credential harvesting, shell spawning, or backdoor logic, but does use dynamic code generation (`new Function`), dynamic `require`, and process-level hooks that are low-risk in context yet noteworthy red-flag patterns in third-party code.
- `dist/emnapi.cjs.js` (safe): No malicious patterns detected; the code is a legitimate Node-API/eCosystem helper library with no data exfiltration, credential harvesting, obfuscation, backdoors, or suspicious runtime behavior.
- `dist/emnapi.js` (safe): No malicious patterns detected; the code is a legitimate Node-API runtime implementation with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `index.js` (safe): Standard conditional module export based on NODE_ENV; no malicious patterns detected

## Version ranges

None of the 3 scanned versions of @emnapi/runtime are flagged high or critical. The latest scanned version, 1.11.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.0.0-alpha.3 (`2.0.0-alpha.3`): not scanned
- 1.10.0 – 1.11.3 (`>=1.10.0 <=1.11.3`): medium (Dynamic code execution)
- 1.4.5 – 1.7.1 (`>=1.4.5 <=1.7.1`): not scanned

## Scanned versions

- [1.11.3](https://security.togoder.click/npm/@emnapi/runtime@1.11.3): medium, 2026-10-06T14:11:03.000Z
- [1.11.1](https://security.togoder.click/npm/@emnapi/runtime@1.11.1): medium, 2026-10-06T14:12:37.000Z
- [1.10.0](https://security.togoder.click/npm/@emnapi/runtime@1.10.0): medium, 2026-10-06T14:13:31.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
