# @emnapi/wasi-threads@1.2.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:24.000Z
- Files reviewed: 6
- Findings: 2 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @emnapi/wasi-threads@1.2.2 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution via Error constructor lookup

Finding ID: `NPS-3E3BEB6ECADB`

File: `dist/wasi-threads.esm-bundler.js:54`

deserizeErrorFromBuffer uses globalThis[name] to look up an Error constructor from an untrusted message name, allowing a worker that controls the shared buffer to potentially instantiate arbitrary global constructors with attacker-controlled input.

### [medium] Cross-thread message passing with untrusted input

Finding ID: `NPS-FF5D2F7EC1E7`

File: `dist/wasi-threads.esm-bundler.js:373`

ThreadManager and ThreadMessageHandler process structured messages (__emnapi__ protocol) from workers using postMessage/onmessage. Payloads including wasmModule, wasmMemory, startArg, and errorOrTid are handled without validation, relying entirely on trust in the worker boundary.

### [low] WeakMap/buffer used for cross-worker error serialization

Finding ID: `NPS-09538C52BCC6`

File: `dist/wasi-threads.esm-bundler.js:22`

Errors are serialized into a SharedArrayBuffer and deserialized by reconstructing stack/name/message. This involves copying stack traces across worker boundaries, which may leak internal implementation details.

### [low] Proxy-based export wrapping

Finding ID: `NPS-25F6D48BA2F5`

File: `dist/wasi-threads.esm-bundler.js:520`

createInstanceProxy uses a Proxy with a get trap that intercepts property lookups and can alter access to instance exports. While it appears to be for legitimate ABI compatibility, it alters normal object behavior and could mask malicious modifications.

### [low] Atomics.wait blocking on shared state

Finding ID: `NPS-DBF9D10B2558`

File: `dist/wasi-threads.esm-bundler.js:710`

threadSpawn blocks the main thread on Atomics.wait(sab, 0, 0) (potentially unbounded if a numeric timeout is not provided), which can cause denial of service if a worker fails to notify.

## Files reviewed

- `dist/wasi-threads.esm-bundler.js` (medium): The file is a legitimate Emscripten/emnapi WASI threads support library, but it handles untrusted cross-worker messages and performs dynamic constructor lookup, which are moderate risk patterns rather than clear malicious behavior.
- `dist/wasi-threads.cjs.js` (safe): No malicious patterns detected; this is a legitimate WebAssembly WASI threads runtime library with no network exfiltration, credential harvesting, obfuscation, or process spawning code.
- `dist/wasi-threads.js` (safe): No malicious patterns detected; the code is a legitimate WASI threads implementation for WebAssembly multithreading.
- `dist/wasi-threads.min.mjs` (safe): No malicious patterns detected; the code implements WebAssembly threads and WASI thread management without any data exfiltration, credential harvesting, obfuscation, or other red-flag behaviors.
- `dist/wasi-threads.mjs` (safe): No malicious patterns detected; this is a legitimate WASI threads/WebAssembly worker-thread management library.
- `index.js` (safe): No malicious patterns detected

## Version ranges

1 of 3 scanned versions of @emnapi/wasi-threads are flagged: 1.2.3 (critical). The latest scanned version, 2.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.0.1 (`2.0.1`): not scanned
- 1.2.3 (`1.2.3`): critical (Dynamic code execution +1 more)
- 1.2.2 (`1.2.2`): medium (Dynamic code execution via Error constructor lookup +1 more)
- 1.2.1 (`1.2.1`): clean
- 1.0.4 – 1.1.0 (`>=1.0.4 <=1.1.0`): not scanned
- Flagged file `dist/wasi-threads.js` (critical) present in 1.2.3; finding IDs `NPS-76A90B79C450`

## Scanned versions

- [1.2.3](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.3): critical, 2026-10-06T14:11:02.000Z
- [1.2.2](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.2): medium, 2026-10-06T14:12:24.000Z
- [1.2.1](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.1): safe, 2026-10-06T14:13:30.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
