# @img/sharp-linux-s390x@0.35.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:11.000Z
- Files reviewed: 1
- Findings: 2 medium severity findings
- Report: https://security.togoder.click/npm/@img/sharp-linux-s390x
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @img/sharp-linux-s390x@0.35.5 on Oct 6, 2026. An AI review of 1 source file produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Platform-specific binary loading

Finding ID: `NPS-FA02857870E0`

File: `index.cjs:2`

The code requires a platform-specific native module ('sharp-linux-s390x-0.35.5.node') and optionally resolves a related libvips binary. While this is typical for native Node modules, it means the package executes native code at import time, which could contain malicious behavior not visible in this JavaScript wrapper.

### [medium] Import-time code execution

Finding ID: `NPS-1CA55D9D6B28`

File: `index.cjs:2`

The module loads a native .node binary as part of its main export. Native modules run compiled machine code at require/import time, bypassing JavaScript sandboxing and static analysis. This is a common vector for hiding malicious payloads in third-party packages.

## Files reviewed

- `index.cjs` (medium): The code is a thin wrapper for a platform-specific native binary; while no direct malicious patterns are visible, loading an opaque .node module at import time warrants caution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
