Summary
Togoder Security scanned the npm package @npmcli/agent@4.0.2 on Oct 6, 2026. An AI review of 6 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic module loading
NPS-6FF34ED1EC83
The module requires several third-party proxy agent packages (http-proxy-agent, https-proxy-agent, socks-proxy-agent) and lru-cache. These are known packages, but the dependency chain should be verified for supply-chain risk since they execute on import.
Environment variable harvesting
NPS-F82EAE378AC2
The module reads process.env at import time, collecting proxy-related environment variables (https_proxy, http_proxy, proxy, no_proxy). While these are standard proxy config variables, this top-level execution and environment access could be used to silently collect configuration from the host environment.
Proxy configuration handling
NPS-303A8AFEE346
Proxy URLs (which may contain embedded credentials such as http://user:pass@host) are parsed and used to instantiate agent objects. No direct exfiltration occurs in this file, but proxy credentials are handled and could be logged or leaked by callers.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/proxy.js | medium | The file is a proxy configuration utility that reads standard proxy environment variables and manages proxy agents; no active exfiltration, code execution, or backdoor behavior is present, but it does access process.env and handles potentially credential-bearing proxy URLs. |
| lib/agents.js | safe | No malicious patterns detected; the code is a legitimate HTTP agent implementation with proxy support, timeout handling, and connection management. |
| lib/dns.js | safe | No malicious patterns detected |
| lib/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | No malicious patterns detected; the module appears to be a standard HTTP agent/proxy configuration utility. |
| lib/options.js | safe | No malicious patterns detected; the file only normalizes and caches network agent options. |
Scanned versions of @npmcli/agent
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 4.0.2 | Needs review | 6 | Oct 6, 2026 |
Frequently asked questions
Is @npmcli/agent safe to use?
No confirmed malware was found in @npmcli/agent@4.0.2, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does @npmcli/agent contain malware?
No malware was identified in @npmcli/agent@4.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @npmcli/agent checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @npmcli/agent together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @npmcli/agent@4.0.2, cost nothing.