Togoder security

npm package security report

@napi-rs/wasm-runtime@1.2.4 security report

Risky patterns found that deserve a look.

Needs review Version 1.2.4 Files reviewed 6 Size 760.0 KB Scanned

Summary

Togoder Security scanned the npm package @napi-rs/wasm-runtime@1.2.4 on Oct 6, 2026. An AI review of 6 source files produced 1 high, 4 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
4
medium
6
low

Findings 11

high

prototype pollution / unsafe deserialization

NPS-3628160A5766

decodeValue reconstructs object prototypes based on a __constructor__ field embedded in JSON payloads. An attacker controlling the message payload can set __constructor__ to any key on memfs, and Object.setPrototypeOf(obj, memfs[ctor].prototype) is executed without validation. Combined with globalThis[name] lookup for __error__, this permits constructing arbitrary global objects from untrusted input, potentially enabling prototype pollution or unexpected object instantiation.

fs-proxy.js
medium

Unvalidated dynamic property access on memfs

NPS-17CD01894DAA

decodeValue and loadConstructor use attacker-controlled JSON properties (__constructor__) to index into the memfs object via memfs[ctor].prototype. A crafted message could set ctor to values like '__proto__' or 'constructor', leading to prototype pollution or access to unintended object properties. While this is a message-passing boundary rather than direct external input, the values come from another context and are not validated against a whitelist of expected fs constructors.

dist/fs-proxy.cjs:128
medium

Prototype manipulation from serialized data

NPS-FC7CB8DC1A48

loadConstructor calls Object.setPrototypeOf(obj, memfs[ctor].prototype) using a string read from the deserialized payload. Combined with the __constructor__ field being written into arbitrary nested objects during encoding, this allows deserialized objects to have their prototype replaced based on data received over the message channel. This could be abused for prototype confusion or sandbox escape depending on what memfs contains.

dist/fs-proxy.cjs:129
medium

unsafe dynamic property access

NPS-AC80B010781C

createFsProxy uses a Proxy get handler that returns a function invoking fs[type] where type is supplied by the caller via postMessage. If type is not a legitimate fs method name (e.g. 'constructor', 'toString', '__proto__'), the call may resolve to an unexpected function or cause errors. This is an uncontrolled dynamic dispatch pattern that can expose unintended object members.

fs-proxy.js
medium

arbitrary global constructor invocation

NPS-5479CE692CC0

In decodeValue, when obj.__error__ is present, the code performs globalThis[name] and instantiates new ErrorConstructor(obj.message). Since name is attacker-controlled, this can invoke arbitrary global constructors. While limited to constructors with a single argument, this is still an unsafe pattern driven by untrusted input.

fs-proxy.js
low

Dynamic error constructor lookup

NPS-0E2E3BC251A1

When decoding error objects, the code does globalThis[name] where name comes from the serialized __error__ field. This resolves arbitrary global properties by name and constructs them with new ErrorConstructor(obj.message). While it falls back to Error and appears limited to constructing errors, resolving arbitrary globals from untrusted serialized data is a risky pattern that could be leveraged if globalThis is extended elsewhere.

dist/fs-proxy.cjs:139
low

SharedArrayBuffer synchronization with Atomics.wait

NPS-612B6C9C3478

The proxy uses SharedArrayBuffer and Atomics.wait to block until the worker responds. If the receiving side never notifies (e.g., due to a crash or malicious peer), the calling thread can hang indefinitely. There is no timeout, which could be abused for denial of service in a multi-tenant or untrusted-worker scenario.

dist/fs-proxy.cjs:191
low

unbounded recursive traversal

NPS-9D29F4B1AAB4

storeConstructor and loadConstructor recursively walk Object.values of arbitrary objects without depth limits. Deeply nested or cyclic structures (partially mitigated by WeakSet) from untrusted input can cause stack exhaustion or excessive CPU usage, a potential denial-of-service vector.

fs-proxy.js
low

payload size handling

NPS-8FE71CA80374

encodeValue for type 6 (JSON) and type 4 (string) does not enforce the RESPONSE_PAYLOAD_SIZE limit before returning. writeResponsePayload throws on overflow, but in the success path this throw happens after partial state setup, and in the error path a fallback overflow handling exists. The JSON path is not explicitly bounded before serialization, allowing large in-memory strings to be produced before the size check.

fs-proxy.js
low

Dynamic module resolution via re-export

NPS-B69FF855A8B9

The wildcard re-export of @tybys/wasm-util and named re-exports from local files (./dist/emnapi-plugins.js, ./fs-proxy.js) mean that importing this module eagerly loads and exposes additional code paths not shown in this file. Without auditing those referenced modules, this file cannot be considered fully benign.

runtime.js
low

Wildcard re-export

NPS-2DE520B06ECA

The file contains export * from '@tybys/wasm-util', which re-exports all members from an external dependency. This can unintentionally expose or propagate dangerous functions from that package and makes the public API surface non-explicit and harder to audit.

runtime.js:35

Files reviewed

FileVerdictWhat the reviewer saw
dist/fs-proxy.cjs medium The fs-proxy module is a memfs RPC bridge with no obvious exfiltration, shell, or install-time code, but it deserializes attacker-influenced JSON and uses unvalidated strings to index memfs and globalThis for prototype/constructor restoration, creating prototype-pollution and object-confusion risks.
fs-proxy.js medium This file is a message-passing FS proxy with no network, process, or filesystem exfiltration, but it contains unsafe deserialization and dynamic dispatch patterns that could be exploited if message payloads are not fully trusted.
runtime.js medium No overt malicious behavior is present in this file, but wildcard and cross-file re-exports prevent a complete safety determination of the runtime's effective behavior.
dist/emnapi-plugins.cjs safe The code is the legitimate @emnapi/core async-work and threadsafe-function plugin implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or unauthorized network/file/process activity.
dist/emnapi-plugins.js safe The file contains standard @emnapi/core WebAssembly plugin implementations for async work and threadsafe functions with no malicious patterns, exfiltration, credential harvesting, or suspicious behavior detected.
runtime.cjs safe No malicious patterns detected; this file only aggregates and re-exports legitimate WASI/emnapi runtime utilities from known dependencies and local relative modules.

Affected version ranges

None of the 2 scanned versions of @napi-rs/wasm-runtime are flagged high or critical. The latest scanned version, 1.2.4, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.2.41.2.4
VersionsVerdictCountRangeTop findings
1.2.4 Needs review 1 1.2.4 prototype pollution / unsafe deserialization; Unvalidated dynamic property access on memfs
1.1.6 – 1.2.2 Not scanned 2 >=1.1.6 <=1.2.2
1.1.4 Needs review 1 1.1.4 Unsafe deserialization / prototype pollution; Attacker-controlled function invocation via Proxy
0.2.4 – 0.2.12 Not scanned 2 >=0.2.4 <=0.2.12

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @napi-rs/wasm-runtime

VersionVerdictFilesScanned
1.2.4 Needs review 6 Oct 6, 2026
1.1.4 Needs review 4 Oct 6, 2026

Frequently asked questions

Is @napi-rs/wasm-runtime safe to use?

No confirmed malware was found in @napi-rs/wasm-runtime@1.2.4, but the review flagged 1 high, 4 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @napi-rs/wasm-runtime contain malware?

No malware was identified in @napi-rs/wasm-runtime@1.2.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @napi-rs/wasm-runtime checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @napi-rs/wasm-runtime together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @napi-rs/wasm-runtime@1.2.4, cost nothing.

Related security reports