# @emnapi/wasi-threads@1.2.3 security report (npm)

- Verdict: **Critical risk** (risk level: critical)
- Scanned: 2026-10-06T14:11:02.000Z
- Files reviewed: 6
- Findings: 1 high, 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @emnapi/wasi-threads@1.2.3 on Oct 6, 2026. An AI review of 6 source files produced 1 high, 1 medium, 3 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

## Findings

### [high] Dynamic code execution

Finding ID: `NPS-76A90B79C450`

File: `dist/wasi-threads.js:92`

The code uses `new Function()` to create a constructor for an error object. This is a form of dynamic code execution which can be exploited if the input is controlled by an attacker, though here it is used to reconstruct an error type from a string name. While the name is obtained from a SharedArrayBuffer that is written by another worker, the name is used as a property lookup on `globalThis` and then called as a constructor. If an attacker can control the error name, they might be able to invoke arbitrary global constructors. However, the name is typically fixed strings like 'RuntimeError' or error names from exceptions, but it's still a potential vector.

### [medium] Deserialization of error objects from SharedArrayBuffer

Finding ID: `NPS-A01F67703A25`

File: `dist/wasi-threads.js:92`

The function `deserizeErrorFromBuffer` reconstructs an Error object from data stored in a SharedArrayBuffer. It creates an error using a constructor looked up by name from `globalThis`. If an attacker can write to the SharedArrayBuffer (e.g., in a multi-threaded scenario where another thread is compromised), they could set the error name to a malicious constructor name, potentially leading to code execution. However, this requires a compromised worker thread. The deserialization also uses `Object.defineProperty` to set the stack, which is benign.

### [low] Unvalidated worker URL

Finding ID: `NPS-91D0851FDFB0`

File: `dist/wasi-threads.js`

The `onCreateWorker` option is provided by the user of this package and is used to create a Worker. The package itself does not validate the worker script URL or options. If a consumer passes untrusted input, it could lead to loading malicious code. However, this is expected behavior for a library that abstracts worker creation, and the responsibility lies with the consumer. This is not a direct vulnerability in the package.

### [low] Potential ReDoS or resource exhaustion

Finding ID: `NPS-682F0C6D8754`

File: `dist/wasi-threads.js`

The code includes Atomics.wait with a timeout, but if the timeout is zero or negative, it might cause indefinite waiting or immediate timeout. The logic appears to handle timeouts correctly, but there is a potential for deadlock if workers don't respond. This is more of a reliability issue than a security vulnerability.

### [low] No obvious malicious patterns

Finding ID: `NPS-B3360F23BD01`

File: `dist/wasi-threads.js`

No data exfiltration, environment variable harvesting, obfuscated code, cryptocurrency mining, backdoor installation, file system manipulation, or suspicious network requests were found in this file.

## Files reviewed

- `dist/wasi-threads.js` (critical): The code contains potentially risky dynamic code execution via `new Function()` and error deserialization from shared memory, but no clear malicious intent; however, these patterns could be exploited in a compromised multi-threaded environment.
- `dist/wasi-threads.cjs.js` (safe): No malicious patterns detected; the code implements WASI threads support for WebAssembly with standard worker and shared memory management, without any data exfiltration, credential harvesting, obfuscated execution, or network calls.
- `dist/wasi-threads.esm-bundler.js` (safe): The code implements WebAssembly threads and WASI thread management using standard APIs, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized network/file system access.
- `dist/wasi-threads.min.mjs` (safe): No malicious patterns detected; the code is a legitimate WebAssembly threads/WASI threading library (emnapi/wasi-threads) with no exfiltration, credential harvesting, obfuscation, or shell execution.
- `dist/wasi-threads.mjs` (safe): No malicious patterns detected; the code is a legitimate WASI threads/WebAssembly threading helper library with no data exfiltration, credential harvesting, obfuscation, or process spawning behaviors.
- `index.js` (safe): No malicious patterns detected

## Version ranges

1 of 3 scanned versions of @emnapi/wasi-threads are flagged: 1.2.3 (critical). The latest scanned version, 2.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.0.1 (`2.0.1`): not scanned
- 1.2.3 (`1.2.3`): critical (Dynamic code execution +1 more)
- 1.2.2 (`1.2.2`): medium (Dynamic code execution via Error constructor lookup +1 more)
- 1.2.1 (`1.2.1`): clean
- 1.0.4 – 1.1.0 (`>=1.0.4 <=1.1.0`): not scanned
- Flagged file `dist/wasi-threads.js` (critical) present in 1.2.3; finding IDs `NPS-76A90B79C450`

## Scanned versions

- [1.2.3](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.3): critical, 2026-10-06T14:11:02.000Z
- [1.2.2](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.2): medium, 2026-10-06T14:12:24.000Z
- [1.2.1](https://security.togoder.click/npm/@emnapi/wasi-threads@1.2.1): safe, 2026-10-06T14:13:30.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
