Summary
Togoder Security scanned the npm package @napi-rs/wasm-runtime@1.1.4 on Oct 6, 2026. An AI review of 4 source files produced 6 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Unsafe deserialization / prototype pollution
NPS-6D6A903AB04A
The decodeValue function reconstructs objects from JSON and calls Object.setPrototypeOf(obj, memfs[ctor].prototype) based on an attacker-controlled '__constructor__' property. An attacker controlling the postMessage payload can influence the prototype chain of deserialized objects, potentially leading to prototype pollution or unexpected behavior. The code also looks up globalThis[name] for error reconstruction, which can resolve arbitrary global constructors.
Attacker-controlled function invocation via Proxy
NPS-6996EC660A4C
createFsProxy returns a Proxy whose get trap returns a function that invokes fs[type] with attacker-supplied arguments delivered via postMessage. The 'type' property comes from the message and is used directly as a key on the memfs object, so any property/method present on fs can be invoked by a message sender. This is an IPC trust boundary issue if messages can come from untrusted contexts (e.g., cross-origin iframes, workers, or injected scripts).
prototype manipulation via JSON deserialization
NPS-C74C68D807CA
The decodeValue function reads an __constructor__ property from parsed JSON and calls Object.setPrototypeOf(obj, memfs[ctor].prototype). A crafted message could set an object's prototype to an arbitrary constructor's prototype, leading to prototype pollution or type confusion in the receiving context.
unsanitized message channel dispatch
NPS-141A871EF5A4
The onMessage handler trusts the structure of e.data.__fs__ and directly uses sab, type, and payload from it. There is no validation that the sender is authorized or that the SharedArrayBuffer dimensions match expectations, enabling malformed input to reach encode/decode logic.
dynamic property access on filesystem object
NPS-0ADDACF5BF74
The createOnMessage function resolves an arbitrary method name from message data via const fn = fs[type] and invokes it with attacker-controlled arguments (fn.apply(fs, payload)). This allows any method of the memfs instance to be called remotely, potentially exposing unintended filesystem operations if the message channel is reachable by untrusted input.
synchronous blocking / denial of service
NPS-4B2EFB3D0F51
createFsProxy uses Atomics.wait on the main thread, blocking the event loop until a response is posted. If the counterpart is missing, compromised, or slow, this can hang the entire runtime indefinitely.
Untrusted data passed to JSON.parse / BigInt / TextDecoder
NPS-C2FD84509A3B
decodeValue parses payloads received via postMessage without validation, including JSON.parse, BigInt conversion, and Float64Array/Int32Array reinterpretation. Malformed or hostile payloads could trigger unexpected exceptions or resource consumption in the consumer.
error constructor injection
NPS-EDE0D0777E7A
In decodeValue, const ErrorConstructor = globalThis[name] || Error uses the untrusted __error__ string from the payload. Although it falls back to Error, arbitrary global constructors can be invoked, and properties are copied from the decoded object onto the new error instance, which could be abused for object injection.
Potential dynamic module loading / import-time behavior
NPS-C66A1D72919B
The file requires '@emnapi/core', '@emnapi/runtime', '@tybys/wasm-util', and a local './dist/fs-proxy.cjs' module at import time. While these are legitimate-looking dependencies for WebAssembly/N-API interop, loading a local dist file and re-exporting its functions (createFsProxy, createOnMessage) means the package executes whatever logic is in that file upon import. The referenced dist/fs-proxy.cjs is not shown, so its behavior cannot be verified; it could contain filesystem proxying, network access, or other sensitive operations. This warrants caution rather than a clean safe verdict.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/fs-proxy.cjs | medium | The file implements a SharedArrayBuffer-based synchronous RPC bridge to memfs with no obvious exfiltration, credential harvesting, or code execution, but the deserialization and proxy dispatch paths trust postMessage payloads and reconstruct object prototypes based on attacker-influenced fields, warranting caution. |
| fs-proxy.js | medium | The file implements a SharedArrayBuffer-based RPC proxy for memfs that deserializes untrusted messages and dynamically invokes filesystem methods, creating prototype-pollution, method-injection, and denial-of-service risks if the message channel is exposed to untrusted input. |
| runtime.cjs | medium | No overtly malicious code is visible in runtime.cjs itself, but it eagerly loads and re-exports local and third-party modules at import time, and the referenced fs-proxy implementation is not auditable here. |
| runtime.js | safe | The file only contains static re-exports from local and known @emnapi/@tybys packages, with no executable code, dynamic imports, or suspicious patterns. |
Affected version ranges
None of the 2 scanned versions of @napi-rs/wasm-runtime are flagged high or critical. The latest scanned version, 1.2.4, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 1.2.4 | Needs review | 1 | 1.2.4 | prototype pollution / unsafe deserialization; Unvalidated dynamic property access on memfs |
| 1.1.6 – 1.2.2 | Not scanned | 2 | >=1.1.6 <=1.2.2 | |
| 1.1.4 | Needs review | 1 | 1.1.4 | Unsafe deserialization / prototype pollution; Attacker-controlled function invocation via Proxy |
| 0.2.4 – 0.2.12 | Not scanned | 2 | >=0.2.4 <=0.2.12 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @napi-rs/wasm-runtime
Frequently asked questions
Is @napi-rs/wasm-runtime safe to use?
No confirmed malware was found in @napi-rs/wasm-runtime@1.1.4, but the review flagged 6 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does @napi-rs/wasm-runtime contain malware?
No malware was identified in @napi-rs/wasm-runtime@1.1.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @napi-rs/wasm-runtime checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @napi-rs/wasm-runtime together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @napi-rs/wasm-runtime@1.1.4, cost nothing.