Togoder security

npm package security report

@img/sharp-darwin-arm64@0.35.5 security report

Risky patterns found that deserve a look.

Needs review Version 0.35.5 Files reviewed 1 Size 141 B Scanned

Summary

Togoder Security scanned the npm package @img/sharp-darwin-arm64@0.35.5 on Oct 6, 2026. An AI review of 1 source file produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
1
low

Findings 2

medium

Native binary loading

NPS-05BC7CA19381

The file directly loads a native .node binary (./lib/sharp-darwin-arm64-0.35.5.node) via require(). Native modules execute arbitrary machine code at import time and cannot be audited as JavaScript. If this package were compromised, the binary could contain any malicious payload (data exfiltration, backdoors, etc.) invisible to source code review.

index.cjs:2
low

Dynamic module loading

NPS-59C66F79D989

The file attempts to resolve a native binary module path using require.resolve('@img/sharp-libvips-darwin-arm64/binary'). While this is likely part of the sharp image processing library's platform-specific binary loading mechanism, it constitutes dynamic module resolution based on package installation state rather than static imports. This pattern can be abused to load arbitrary native code if the package name or resolution path is influenced by external input, though here it appears hardcoded.

index.cjs:1

Files reviewed

FileVerdictWhat the reviewer saw
index.cjs medium This is a platform-specific loader for the sharp image library that dynamically resolves and loads a native binary; while the code itself contains no obvious malicious logic, loading a native .node binary means the actual executable code is unauditable and could conceal malicious behavior if the package or its dependencies were compromised.

Frequently asked questions

Is @img/sharp-darwin-arm64 safe to use?

No confirmed malware was found in @img/sharp-darwin-arm64@0.35.5, but the review flagged 1 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @img/sharp-darwin-arm64 contain malware?

No malware was identified in @img/sharp-darwin-arm64@0.35.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @img/sharp-darwin-arm64 checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @img/sharp-darwin-arm64 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @img/sharp-darwin-arm64@0.35.5, cost nothing.

Related security reports