Togoder security

npm package security report

@emnapi/wasi-threads@1.2.2 security report

Risky patterns found that deserve a look.

Needs review Version 1.2.2 Files reviewed 6 Size 148.3 KB Scanned

Summary

Togoder Security scanned the npm package @emnapi/wasi-threads@1.2.2 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
3
low

Findings 5

medium

Dynamic code execution via Error constructor lookup

NPS-3E3BEB6ECADB

deserizeErrorFromBuffer uses globalThis[name] to look up an Error constructor from an untrusted message name, allowing a worker that controls the shared buffer to potentially instantiate arbitrary global constructors with attacker-controlled input.

dist/wasi-threads.esm-bundler.js:54
medium

Cross-thread message passing with untrusted input

NPS-FF5D2F7EC1E7

ThreadManager and ThreadMessageHandler process structured messages (__emnapi__ protocol) from workers using postMessage/onmessage. Payloads including wasmModule, wasmMemory, startArg, and errorOrTid are handled without validation, relying entirely on trust in the worker boundary.

dist/wasi-threads.esm-bundler.js:373
low

WeakMap/buffer used for cross-worker error serialization

NPS-09538C52BCC6

Errors are serialized into a SharedArrayBuffer and deserialized by reconstructing stack/name/message. This involves copying stack traces across worker boundaries, which may leak internal implementation details.

dist/wasi-threads.esm-bundler.js:22
low

Proxy-based export wrapping

NPS-25F6D48BA2F5

createInstanceProxy uses a Proxy with a get trap that intercepts property lookups and can alter access to instance exports. While it appears to be for legitimate ABI compatibility, it alters normal object behavior and could mask malicious modifications.

dist/wasi-threads.esm-bundler.js:520
low

Atomics.wait blocking on shared state

NPS-DBF9D10B2558

threadSpawn blocks the main thread on Atomics.wait(sab, 0, 0) (potentially unbounded if a numeric timeout is not provided), which can cause denial of service if a worker fails to notify.

dist/wasi-threads.esm-bundler.js:710

Files reviewed

FileVerdictWhat the reviewer saw
dist/wasi-threads.esm-bundler.js medium The file is a legitimate Emscripten/emnapi WASI threads support library, but it handles untrusted cross-worker messages and performs dynamic constructor lookup, which are moderate risk patterns rather than clear malicious behavior.
dist/wasi-threads.cjs.js safe No malicious patterns detected; this is a legitimate WebAssembly WASI threads runtime library with no network exfiltration, credential harvesting, obfuscation, or process spawning code.
dist/wasi-threads.js safe No malicious patterns detected; the code is a legitimate WASI threads implementation for WebAssembly multithreading.
dist/wasi-threads.min.mjs safe No malicious patterns detected; the code implements WebAssembly threads and WASI thread management without any data exfiltration, credential harvesting, obfuscation, or other red-flag behaviors.
dist/wasi-threads.mjs safe No malicious patterns detected; this is a legitimate WASI threads/WebAssembly worker-thread management library.
index.js safe No malicious patterns detected

Affected version ranges

1 of 3 scanned versions of @emnapi/wasi-threads are flagged: 1.2.3 (critical). The latest scanned version, 2.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.0.42.0.1
VersionsVerdictCountRangeTop findings
2.0.1 Not scanned 1 2.0.1
1.2.3 Critical 1 1.2.3 Dynamic code execution; Deserialization of error objects from SharedArrayBuffer
1.2.2 Needs review 1 1.2.2 Dynamic code execution via Error constructor lookup; Cross-thread message passing with untrusted input
1.2.1 No issues 1 1.2.1
1.0.4 โ€“ 1.1.0 Not scanned 2 >=1.0.4 <=1.1.0

Flagged files across versions

  • critical dist/wasi-threads.js (Dynamic code execution) NPS-76A90B79C450: present in 1.2.3

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @emnapi/wasi-threads

VersionVerdictFilesScanned
1.2.3 Critical risk 6 Oct 6, 2026
1.2.2 Needs review 6 Oct 6, 2026
1.2.1 No issues 6 Oct 6, 2026

Frequently asked questions

Is @emnapi/wasi-threads safe to use?

No confirmed malware was found in @emnapi/wasi-threads@1.2.2, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does @emnapi/wasi-threads contain malware?

No malware was identified in @emnapi/wasi-threads@1.2.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @emnapi/wasi-threads checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @emnapi/wasi-threads together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @emnapi/wasi-threads@1.2.2, cost nothing.

Related security reports