Summary
Togoder Security scanned the npm package @img/sharp-darwin-arm64@0.35.5 on Oct 6, 2026. An AI review of 1 source file produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Native binary loading
NPS-05BC7CA19381
The file directly loads a native .node binary (./lib/sharp-darwin-arm64-0.35.5.node) via require(). Native modules execute arbitrary machine code at import time and cannot be audited as JavaScript. If this package were compromised, the binary could contain any malicious payload (data exfiltration, backdoors, etc.) invisible to source code review.
Dynamic module loading
NPS-59C66F79D989
The file attempts to resolve a native binary module path using require.resolve('@img/sharp-libvips-darwin-arm64/binary'). While this is likely part of the sharp image processing library's platform-specific binary loading mechanism, it constitutes dynamic module resolution based on package installation state rather than static imports. This pattern can be abused to load arbitrary native code if the package name or resolution path is influenced by external input, though here it appears hardcoded.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.cjs | medium | This is a platform-specific loader for the sharp image library that dynamically resolves and loads a native binary; while the code itself contains no obvious malicious logic, loading a native .node binary means the actual executable code is unauditable and could conceal malicious behavior if the package or its dependencies were compromised. |
Scanned versions of @img/sharp-darwin-arm64
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 0.35.5 | Needs review | 1 | Oct 6, 2026 |
Frequently asked questions
Is @img/sharp-darwin-arm64 safe to use?
No confirmed malware was found in @img/sharp-darwin-arm64@0.35.5, but the review flagged 1 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @img/sharp-darwin-arm64 contain malware?
No malware was identified in @img/sharp-darwin-arm64@0.35.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @img/sharp-darwin-arm64 checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @img/sharp-darwin-arm64 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @img/sharp-darwin-arm64@0.35.5, cost nothing.