# @emnapi/wasi-threads@1.2.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:30.000Z
- Files reviewed: 6
- Findings: no findings
- Report: https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @emnapi/wasi-threads@1.2.1 on Oct 6, 2026. An AI review of 6 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/wasi-threads.cjs.js` (safe): No malicious patterns detected; the code is a legitimate WebAssembly threads (WASI-threads/emnapi) library without data exfiltration, credential harvesting, obfuscation, or process spawning.
- `dist/wasi-threads.esm-bundler.js` (safe): This is a legitimate WebAssembly threads library (emnapi/wasi-threads) implementing worker thread management and WASI support without any malicious patterns.
- `dist/wasi-threads.js` (safe): No malicious patterns detected; the code is a legitimate WebAssembly WASI threads implementation with no data exfiltration, credential harvesting, shell execution, or other security concerns.
- `dist/wasi-threads.min.mjs` (safe): No malicious patterns detected; this is a legitimate WASI threads polyfill with no exfiltration, obfuscation, credential harvesting, or suspicious network/file/process activity.
- `dist/wasi-threads.mjs` (safe): The code is a legitimate WASI threads implementation for WebAssembly with no malicious patterns detected.
- `index.js` (safe): No malicious patterns detected

## Version ranges

1 of 3 scanned versions of @emnapi/wasi-threads are flagged: 1.2.3 (critical). The latest scanned version, 2.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.0.1 (`2.0.1`): not scanned
- 1.2.3 (`1.2.3`): critical (Dynamic code execution +1 more)
- 1.2.2 (`1.2.2`): medium (Dynamic code execution via Error constructor lookup +1 more)
- 1.2.1 (`1.2.1`): clean
- 1.0.4 – 1.1.0 (`>=1.0.4 <=1.1.0`): not scanned
- Flagged file `dist/wasi-threads.js` (critical) present in 1.2.3; finding IDs `NPS-76A90B79C450`

## Scanned versions

- [1.2.3](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.3): critical, 2026-10-06T14:11:02.000Z
- [1.2.2](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.2): medium, 2026-10-06T14:12:24.000Z
- [1.2.1](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.1): safe, 2026-10-06T14:13:30.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
