# @humanwhocodes/module-importer@1.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:07.000Z
- Files reviewed: 4
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@humanwhocodes/module-importer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @humanwhocodes/module-importer@1.0.1 on Oct 6, 2026. An AI review of 4 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with relative path

Finding ID: `NPS-16B5BB1CD3AD`

File: `src/module-importer.js:17`

The code uses createRequire to dynamically load './module-importer.cjs' at import time. While the path is static and relative, this pattern bypasses ES module static analysis and could be exploited if the package is compromised or if the .cjs file is replaced. It also runs code at import time, which is a common vector for malicious payloads in supply chain attacks.

### [low] Import-time code execution

Finding ID: `NPS-74570975469C`

File: `dist/module-importer.cjs:15`

Top-level code executes at import time, including file URL resolution and dynamic require. No exfiltration, credential harvesting, obfuscation, network activity, or process spawning is present, so the runtime surface is limited to loading a sibling module.

### [low] URL construction quirk

Finding ID: `NPS-86694225FE18`

File: `dist/module-importer.cjs:15`

Uses 'u' + 'rl' string concatenation to invoke the URL constructor. This is benign obfuscation to avoid bundler static analysis, not malicious payload hiding, but it warrants noting as an unusual coding pattern.

### [low] Dynamic module loading

Finding ID: `NPS-B448593BBFC1`

File: `dist/module-importer.cjs:18`

The file uses module.createRequire to create a require function pointing at __dirname and then dynamically loads './module-importer.cjs'. While this is likely an intentional pattern for dual CJS/ESM support, dynamic require with computed paths can be abused if the loading path is ever influenced by external input.

## Files reviewed

- `dist/module-importer.cjs` (medium): No malicious indicators found; only benign dynamic module loading and trivial string obfuscation for bundler compatibility.
- `src/module-importer.js` (medium): The file uses createRequire to load a local CommonJS module at import time, which is a benign but potentially risky pattern that could be abused if the package is compromised.
- `dist/module-importer.js` (safe): No malicious patterns detected; the file is a standard ESM wrapper around a CommonJS module.
- `src/module-importer.cjs` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
