Summary
Togoder Security scanned the npm package @msgpack/msgpack@3.1.3 on Oct 4, 2026. An AI review of 53 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist.cjs/CachedKeyDecoder.cjs | safe | No malicious patterns detected; the code implements a caching key decoder using only local memory operations. |
| dist.cjs/DecodeError.cjs | safe | No malicious patterns detected; the code is a simple custom error class with standard prototype chain fix. |
| dist.cjs/Decoder.cjs | safe | No malicious patterns detected; this is a standard MessagePack decoder implementation with no network, filesystem, process, or credential access. |
| dist.cjs/Encoder.cjs | safe | No malicious patterns detected; the file is a legitimate MessagePack Encoder implementation from the @msgpack/msgpack library. |
| dist.cjs/ExtData.cjs | safe | No malicious patterns detected; the file defines a simple ExtData class with no external I/O, code execution, or install-time behavior. |
| dist.cjs/ExtensionCodec.cjs | safe | Code implements a standard MessagePack ExtensionCodec with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist.cjs/context.cjs | safe | No malicious patterns detected |
| dist.cjs/decode.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.cjs/decodeAsync.cjs | safe | The code is a straightforward async stream decoder wrapper with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist.cjs/encode.cjs | safe | No malicious patterns detected |
| dist.cjs/index.cjs | safe | No malicious patterns detected; the file is a standard module index re-exporting symbols from other local modules. |
| dist.cjs/timestamp.cjs | safe | No malicious patterns detected |
| dist.cjs/utils/int.cjs | safe | No malicious patterns detected |
| dist.cjs/utils/prettyByte.cjs | safe | No malicious patterns detected |
| dist.cjs/utils/stream.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.cjs/utils/typedArrays.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.cjs/utils/utf8.cjs | safe | The file contains only standard UTF-8 encoding/decoding utilities using TextEncoder/TextDecoder with no network, filesystem, process, or obfuscation concerns. |
| dist.esm/CachedKeyDecoder.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/DecodeError.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/Decoder.mjs | safe | This is a MessagePack decoder implementation with no malicious patterns detected. |
| dist.esm/Encoder.mjs | safe | No malicious patterns detected; the code is a standard MessagePack encoder implementation with no network, filesystem, process, or dynamic execution activity. |
| dist.esm/ExtData.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/ExtensionCodec.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/context.mjs | safe | This is an empty ES module re-export file with only a sourcemap comment, containing no code and no malicious patterns. |
| dist.esm/decode.mjs | safe | Cleared by Jev triage; no further analysis needed |
Show 28 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist.esm/decodeAsync.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/encode.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/timestamp.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/utils/int.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/utils/prettyByte.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/utils/stream.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/utils/typedArrays.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist.esm/utils/utf8.mjs | safe | The code implements standard UTF-8 encoding/decoding utilities using TextEncoder/TextDecoder with no network, filesystem, process execution, or obfuscated behavior. |
| dist.umd/msgpack.js | safe | No malicious patterns detected; this is a legitimate MessagePack serialization library with no network, filesystem, process execution, or credential harvesting behavior. |
| mod.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/CachedKeyDecoder.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/DecodeError.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/Decoder.ts | safe | This is the standard MessagePack Decoder implementation with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network/file system operations. |
| src/Encoder.ts | safe | No malicious patterns detected; this is a legitimate MessagePack Encoder implementation with no network, filesystem, process, or dynamic code execution behavior. |
| src/ExtData.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/ExtensionCodec.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/context.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/decode.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/decodeAsync.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/encode.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/timestamp.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/int.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/prettyByte.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/stream.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/typedArrays.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/utf8.ts | safe | No malicious patterns detected; the code is a standard UTF-8 encoder/decoder implementation with no network, filesystem, process, or dynamic execution activity. |
Scanned versions of @msgpack/msgpack
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 3.1.3 | No issues | 53 | Oct 4, 2026 |
Frequently asked questions
Is @msgpack/msgpack safe to use?
Our AI source review of @msgpack/msgpack@3.1.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @msgpack/msgpack contain malware?
No malware was identified in @msgpack/msgpack@3.1.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @msgpack/msgpack checked?
Togoder Security downloaded the published npm package and had an AI model read its 53 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @msgpack/msgpack together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @msgpack/msgpack@3.1.3, cost nothing.