Togoder security

npm package security report

@humanwhocodes/module-importer@1.0.1 security report

Risky patterns found that deserve a look.

Needs review Version 1.0.1 Files reviewed 4 Size 4.6 KB Scanned

Summary

Togoder Security scanned the npm package @humanwhocodes/module-importer@1.0.1 on Oct 6, 2026. An AI review of 4 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

Dynamic module loading with relative path

NPS-16B5BB1CD3AD

The code uses createRequire to dynamically load './module-importer.cjs' at import time. While the path is static and relative, this pattern bypasses ES module static analysis and could be exploited if the package is compromised or if the .cjs file is replaced. It also runs code at import time, which is a common vector for malicious payloads in supply chain attacks.

src/module-importer.js:17
low

Import-time code execution

NPS-74570975469C

Top-level code executes at import time, including file URL resolution and dynamic require. No exfiltration, credential harvesting, obfuscation, network activity, or process spawning is present, so the runtime surface is limited to loading a sibling module.

dist/module-importer.cjs:15
low

URL construction quirk

NPS-86694225FE18

Uses 'u' + 'rl' string concatenation to invoke the URL constructor. This is benign obfuscation to avoid bundler static analysis, not malicious payload hiding, but it warrants noting as an unusual coding pattern.

dist/module-importer.cjs:15
low

Dynamic module loading

NPS-B448593BBFC1

The file uses module.createRequire to create a require function pointing at __dirname and then dynamically loads './module-importer.cjs'. While this is likely an intentional pattern for dual CJS/ESM support, dynamic require with computed paths can be abused if the loading path is ever influenced by external input.

dist/module-importer.cjs:18

Files reviewed

FileVerdictWhat the reviewer saw
dist/module-importer.cjs medium No malicious indicators found; only benign dynamic module loading and trivial string obfuscation for bundler compatibility.
src/module-importer.js medium The file uses createRequire to load a local CommonJS module at import time, which is a benign but potentially risky pattern that could be abused if the package is compromised.
dist/module-importer.js safe No malicious patterns detected; the file is a standard ESM wrapper around a CommonJS module.
src/module-importer.cjs safe No malicious patterns detected

Frequently asked questions

Is @humanwhocodes/module-importer safe to use?

No confirmed malware was found in @humanwhocodes/module-importer@1.0.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does @humanwhocodes/module-importer contain malware?

No malware was identified in @humanwhocodes/module-importer@1.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @humanwhocodes/module-importer checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @humanwhocodes/module-importer together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @humanwhocodes/module-importer@1.0.1, cost nothing.

Related security reports