Summary
Togoder Security scanned the npm package @emnapi/wasi-threads@1.2.2 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Dynamic code execution via Error constructor lookup
NPS-3E3BEB6ECADB
deserizeErrorFromBuffer uses globalThis[name] to look up an Error constructor from an untrusted message name, allowing a worker that controls the shared buffer to potentially instantiate arbitrary global constructors with attacker-controlled input.
Cross-thread message passing with untrusted input
NPS-FF5D2F7EC1E7
ThreadManager and ThreadMessageHandler process structured messages (__emnapi__ protocol) from workers using postMessage/onmessage. Payloads including wasmModule, wasmMemory, startArg, and errorOrTid are handled without validation, relying entirely on trust in the worker boundary.
WeakMap/buffer used for cross-worker error serialization
NPS-09538C52BCC6
Errors are serialized into a SharedArrayBuffer and deserialized by reconstructing stack/name/message. This involves copying stack traces across worker boundaries, which may leak internal implementation details.
Proxy-based export wrapping
NPS-25F6D48BA2F5
createInstanceProxy uses a Proxy with a get trap that intercepts property lookups and can alter access to instance exports. While it appears to be for legitimate ABI compatibility, it alters normal object behavior and could mask malicious modifications.
Atomics.wait blocking on shared state
NPS-DBF9D10B2558
threadSpawn blocks the main thread on Atomics.wait(sab, 0, 0) (potentially unbounded if a numeric timeout is not provided), which can cause denial of service if a worker fails to notify.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/wasi-threads.esm-bundler.js | medium | The file is a legitimate Emscripten/emnapi WASI threads support library, but it handles untrusted cross-worker messages and performs dynamic constructor lookup, which are moderate risk patterns rather than clear malicious behavior. |
| dist/wasi-threads.cjs.js | safe | No malicious patterns detected; this is a legitimate WebAssembly WASI threads runtime library with no network exfiltration, credential harvesting, obfuscation, or process spawning code. |
| dist/wasi-threads.js | safe | No malicious patterns detected; the code is a legitimate WASI threads implementation for WebAssembly multithreading. |
| dist/wasi-threads.min.mjs | safe | No malicious patterns detected; the code implements WebAssembly threads and WASI thread management without any data exfiltration, credential harvesting, obfuscation, or other red-flag behaviors. |
| dist/wasi-threads.mjs | safe | No malicious patterns detected; this is a legitimate WASI threads/WebAssembly worker-thread management library. |
| index.js | safe | No malicious patterns detected |
Affected version ranges
1 of 3 scanned versions of @emnapi/wasi-threads are flagged: 1.2.3 (critical). The latest scanned version, 2.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.0.1 | Not scanned | 1 | 2.0.1 | |
| 1.2.3 | Critical | 1 | 1.2.3 | Dynamic code execution; Deserialization of error objects from SharedArrayBuffer |
| 1.2.2 | Needs review | 1 | 1.2.2 | Dynamic code execution via Error constructor lookup; Cross-thread message passing with untrusted input |
| 1.2.1 | No issues | 1 | 1.2.1 | |
| 1.0.4 โ 1.1.0 | Not scanned | 2 | >=1.0.4 <=1.1.0 |
Flagged files across versions
- critical
dist/wasi-threads.js (Dynamic code execution)
NPS-76A90B79C450: present in 1.2.3
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @emnapi/wasi-threads
Frequently asked questions
Is @emnapi/wasi-threads safe to use?
No confirmed malware was found in @emnapi/wasi-threads@1.2.2, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does @emnapi/wasi-threads contain malware?
No malware was identified in @emnapi/wasi-threads@1.2.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @emnapi/wasi-threads checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @emnapi/wasi-threads together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @emnapi/wasi-threads@1.2.2, cost nothing.