Summary
Togoder Security scanned the npm package @humanwhocodes/module-importer@1.0.1 on Oct 6, 2026. An AI review of 4 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Dynamic module loading with relative path
NPS-16B5BB1CD3AD
The code uses createRequire to dynamically load './module-importer.cjs' at import time. While the path is static and relative, this pattern bypasses ES module static analysis and could be exploited if the package is compromised or if the .cjs file is replaced. It also runs code at import time, which is a common vector for malicious payloads in supply chain attacks.
Import-time code execution
NPS-74570975469C
Top-level code executes at import time, including file URL resolution and dynamic require. No exfiltration, credential harvesting, obfuscation, network activity, or process spawning is present, so the runtime surface is limited to loading a sibling module.
URL construction quirk
NPS-86694225FE18
Uses 'u' + 'rl' string concatenation to invoke the URL constructor. This is benign obfuscation to avoid bundler static analysis, not malicious payload hiding, but it warrants noting as an unusual coding pattern.
Dynamic module loading
NPS-B448593BBFC1
The file uses module.createRequire to create a require function pointing at __dirname and then dynamically loads './module-importer.cjs'. While this is likely an intentional pattern for dual CJS/ESM support, dynamic require with computed paths can be abused if the loading path is ever influenced by external input.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/module-importer.cjs | medium | No malicious indicators found; only benign dynamic module loading and trivial string obfuscation for bundler compatibility. |
| src/module-importer.js | medium | The file uses createRequire to load a local CommonJS module at import time, which is a benign but potentially risky pattern that could be abused if the package is compromised. |
| dist/module-importer.js | safe | No malicious patterns detected; the file is a standard ESM wrapper around a CommonJS module. |
| src/module-importer.cjs | safe | No malicious patterns detected |
Frequently asked questions
Is @humanwhocodes/module-importer safe to use?
No confirmed malware was found in @humanwhocodes/module-importer@1.0.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does @humanwhocodes/module-importer contain malware?
No malware was identified in @humanwhocodes/module-importer@1.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @humanwhocodes/module-importer checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @humanwhocodes/module-importer together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @humanwhocodes/module-importer@1.0.1, cost nothing.