Summary
Togoder Security scanned the npm package @emnapi/wasi-threads@1.2.3 on Oct 6, 2026. An AI review of 6 source files produced 1 high, 1 medium, 3 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.
Findings 5
Dynamic code execution
NPS-76A90B79C450
The code uses new Function() to create a constructor for an error object. This is a form of dynamic code execution which can be exploited if the input is controlled by an attacker, though here it is used to reconstruct an error type from a string name. While the name is obtained from a SharedArrayBuffer that is written by another worker, the name is used as a property lookup on globalThis and then called as a constructor. If an attacker can control the error name, they might be able to invoke arbitrary global constructors. However, the name is typically fixed strings like 'RuntimeError' or error names from exceptions, but it's still a potential vector.
Deserialization of error objects from SharedArrayBuffer
NPS-A01F67703A25
The function deserizeErrorFromBuffer reconstructs an Error object from data stored in a SharedArrayBuffer. It creates an error using a constructor looked up by name from globalThis. If an attacker can write to the SharedArrayBuffer (e.g., in a multi-threaded scenario where another thread is compromised), they could set the error name to a malicious constructor name, potentially leading to code execution. However, this requires a compromised worker thread. The deserialization also uses Object.defineProperty to set the stack, which is benign.
Unvalidated worker URL
NPS-91D0851FDFB0
The onCreateWorker option is provided by the user of this package and is used to create a Worker. The package itself does not validate the worker script URL or options. If a consumer passes untrusted input, it could lead to loading malicious code. However, this is expected behavior for a library that abstracts worker creation, and the responsibility lies with the consumer. This is not a direct vulnerability in the package.
Potential ReDoS or resource exhaustion
NPS-682F0C6D8754
The code includes Atomics.wait with a timeout, but if the timeout is zero or negative, it might cause indefinite waiting or immediate timeout. The logic appears to handle timeouts correctly, but there is a potential for deadlock if workers don't respond. This is more of a reliability issue than a security vulnerability.
No obvious malicious patterns
NPS-B3360F23BD01
No data exfiltration, environment variable harvesting, obfuscated code, cryptocurrency mining, backdoor installation, file system manipulation, or suspicious network requests were found in this file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/wasi-threads.js | critical | The code contains potentially risky dynamic code execution via new Function() and error deserialization from shared memory, but no clear malicious intent; however, these patterns could be exploited in a compromised multi-threaded environment. |
| dist/wasi-threads.cjs.js | safe | No malicious patterns detected; the code implements WASI threads support for WebAssembly with standard worker and shared memory management, without any data exfiltration, credential harvesting, obfuscated execution, or network calls. |
| dist/wasi-threads.esm-bundler.js | safe | The code implements WebAssembly threads and WASI thread management using standard APIs, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized network/file system access. |
| dist/wasi-threads.min.mjs | safe | No malicious patterns detected; the code is a legitimate WebAssembly threads/WASI threading library (emnapi/wasi-threads) with no exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/wasi-threads.mjs | safe | No malicious patterns detected; the code is a legitimate WASI threads/WebAssembly threading helper library with no data exfiltration, credential harvesting, obfuscation, or process spawning behaviors. |
| index.js | safe | No malicious patterns detected |
Affected version ranges
1 of 3 scanned versions of @emnapi/wasi-threads are flagged: 1.2.3 (critical). The latest scanned version, 2.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.0.1 | Not scanned | 1 | 2.0.1 | |
| 1.2.3 | Critical | 1 | 1.2.3 | Dynamic code execution; Deserialization of error objects from SharedArrayBuffer |
| 1.2.2 | Needs review | 1 | 1.2.2 | Dynamic code execution via Error constructor lookup; Cross-thread message passing with untrusted input |
| 1.2.1 | No issues | 1 | 1.2.1 | |
| 1.0.4 โ 1.1.0 | Not scanned | 2 | >=1.0.4 <=1.1.0 |
Flagged files across versions
- critical
dist/wasi-threads.js (Dynamic code execution)
NPS-76A90B79C450: present in 1.2.3
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @emnapi/wasi-threads
Frequently asked questions
Is @emnapi/wasi-threads safe to use?
@emnapi/wasi-threads@1.2.3 has 1 high, 1 medium, 3 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.
Does @emnapi/wasi-threads contain malware?
The latest scan of @emnapi/wasi-threads (1.2.3) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.
How was @emnapi/wasi-threads checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @emnapi/wasi-threads together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @emnapi/wasi-threads@1.2.3, cost nothing.