# @img/sharp-darwin-arm64@0.35.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:10.000Z
- Files reviewed: 1
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@img/sharp-darwin-arm64
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @img/sharp-darwin-arm64@0.35.5 on Oct 6, 2026. An AI review of 1 source file produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Native binary loading

Finding ID: `NPS-05BC7CA19381`

File: `index.cjs:2`

The file directly loads a native .node binary (./lib/sharp-darwin-arm64-0.35.5.node) via require(). Native modules execute arbitrary machine code at import time and cannot be audited as JavaScript. If this package were compromised, the binary could contain any malicious payload (data exfiltration, backdoors, etc.) invisible to source code review.

### [low] Dynamic module loading

Finding ID: `NPS-59C66F79D989`

File: `index.cjs:1`

The file attempts to resolve a native binary module path using require.resolve('@img/sharp-libvips-darwin-arm64/binary'). While this is likely part of the sharp image processing library's platform-specific binary loading mechanism, it constitutes dynamic module resolution based on package installation state rather than static imports. This pattern can be abused to load arbitrary native code if the package name or resolution path is influenced by external input, though here it appears hardcoded.

## Files reviewed

- `index.cjs` (medium): This is a platform-specific loader for the sharp image library that dynamically resolves and loads a native binary; while the code itself contains no obvious malicious logic, loading a native .node binary means the actual executable code is unauditable and could conceal malicious behavior if the package or its dependencies were compromised.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
