Togoder security

npm package security report

@msgpack/msgpack npm package: is it safe?

No malicious code found.

No issues Version 3.1.3 Files reviewed 53 Size 248.2 KB Scanned

Summary

Togoder Security scanned the npm package @msgpack/msgpack@3.1.3 on Oct 4, 2026. An AI review of 53 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
dist.cjs/CachedKeyDecoder.cjs safe No malicious patterns detected; the code implements a caching key decoder using only local memory operations.
dist.cjs/DecodeError.cjs safe No malicious patterns detected; the code is a simple custom error class with standard prototype chain fix.
dist.cjs/Decoder.cjs safe No malicious patterns detected; this is a standard MessagePack decoder implementation with no network, filesystem, process, or credential access.
dist.cjs/Encoder.cjs safe No malicious patterns detected; the file is a legitimate MessagePack Encoder implementation from the @msgpack/msgpack library.
dist.cjs/ExtData.cjs safe No malicious patterns detected; the file defines a simple ExtData class with no external I/O, code execution, or install-time behavior.
dist.cjs/ExtensionCodec.cjs safe Code implements a standard MessagePack ExtensionCodec with no malicious patterns, network activity, file system access, or dynamic code execution.
dist.cjs/context.cjs safe No malicious patterns detected
dist.cjs/decode.cjs safe Cleared by Jev triage; no further analysis needed
dist.cjs/decodeAsync.cjs safe The code is a straightforward async stream decoder wrapper with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
dist.cjs/encode.cjs safe No malicious patterns detected
dist.cjs/index.cjs safe No malicious patterns detected; the file is a standard module index re-exporting symbols from other local modules.
dist.cjs/timestamp.cjs safe No malicious patterns detected
dist.cjs/utils/int.cjs safe No malicious patterns detected
dist.cjs/utils/prettyByte.cjs safe No malicious patterns detected
dist.cjs/utils/stream.cjs safe Cleared by Jev triage; no further analysis needed
dist.cjs/utils/typedArrays.cjs safe Cleared by Jev triage; no further analysis needed
dist.cjs/utils/utf8.cjs safe The file contains only standard UTF-8 encoding/decoding utilities using TextEncoder/TextDecoder with no network, filesystem, process, or obfuscation concerns.
dist.esm/CachedKeyDecoder.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/DecodeError.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/Decoder.mjs safe This is a MessagePack decoder implementation with no malicious patterns detected.
dist.esm/Encoder.mjs safe No malicious patterns detected; the code is a standard MessagePack encoder implementation with no network, filesystem, process, or dynamic execution activity.
dist.esm/ExtData.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/ExtensionCodec.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/context.mjs safe This is an empty ES module re-export file with only a sourcemap comment, containing no code and no malicious patterns.
dist.esm/decode.mjs safe Cleared by Jev triage; no further analysis needed
Show 28 more files
FileVerdictWhat the reviewer saw
dist.esm/decodeAsync.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/encode.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/index.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/timestamp.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/utils/int.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/utils/prettyByte.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/utils/stream.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/utils/typedArrays.mjs safe Cleared by Jev triage; no further analysis needed
dist.esm/utils/utf8.mjs safe The code implements standard UTF-8 encoding/decoding utilities using TextEncoder/TextDecoder with no network, filesystem, process execution, or obfuscated behavior.
dist.umd/msgpack.js safe No malicious patterns detected; this is a legitimate MessagePack serialization library with no network, filesystem, process execution, or credential harvesting behavior.
mod.ts safe Cleared by Jev triage; no further analysis needed
src/CachedKeyDecoder.ts safe Cleared by Jev triage; no further analysis needed
src/DecodeError.ts safe Cleared by Jev triage; no further analysis needed
src/Decoder.ts safe This is the standard MessagePack Decoder implementation with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network/file system operations.
src/Encoder.ts safe No malicious patterns detected; this is a legitimate MessagePack Encoder implementation with no network, filesystem, process, or dynamic code execution behavior.
src/ExtData.ts safe Cleared by Jev triage; no further analysis needed
src/ExtensionCodec.ts safe Cleared by Jev triage; no further analysis needed
src/context.ts safe Cleared by Jev triage; no further analysis needed
src/decode.ts safe Cleared by Jev triage; no further analysis needed
src/decodeAsync.ts safe Cleared by Jev triage; no further analysis needed
src/encode.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/timestamp.ts safe Cleared by Jev triage; no further analysis needed
src/utils/int.ts safe Cleared by Jev triage; no further analysis needed
src/utils/prettyByte.ts safe Cleared by Jev triage; no further analysis needed
src/utils/stream.ts safe Cleared by Jev triage; no further analysis needed
src/utils/typedArrays.ts safe Cleared by Jev triage; no further analysis needed
src/utils/utf8.ts safe No malicious patterns detected; the code is a standard UTF-8 encoder/decoder implementation with no network, filesystem, process, or dynamic execution activity.

Scanned versions of @msgpack/msgpack

VersionVerdictFilesScanned
3.1.3 No issues 53 Oct 4, 2026

Frequently asked questions

Is @msgpack/msgpack safe to use?

Our AI source review of @msgpack/msgpack@3.1.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @msgpack/msgpack contain malware?

No malware was identified in @msgpack/msgpack@3.1.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @msgpack/msgpack checked?

Togoder Security downloaded the published npm package and had an AI model read its 53 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @msgpack/msgpack together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @msgpack/msgpack@3.1.3, cost nothing.

Related security reports