Summary
Togoder Security scanned the npm package @orval/hono@8.39.0 on Oct 6, 2026. An AI review of 2 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Dynamic import of optional peer dependency
NPS-434AFD40883F
The code lazily imports the 'typescript' module via await import('typescript') inside ensureTypeScript. Dynamic imports with module names can be a red flag if the name were attacker-controlled, but here it is a fixed, well-known package. It is used to parse/generate TypeScript code, which is expected for this code generator (orval). Low risk.
Reads a bundled source file at import time
NPS-623EE449B7BB
At module load time, ZVALIDATOR_SOURCE = fs.readFileSync(nodePath.join(import.meta.dirname, "zValidator.ts")).toString("utf8") reads a sibling file. This is top-level code executed on import and reads from the package's own directory. It is not exfiltrating data, but it is side-effectful code at import time reading from the filesystem.
Filesystem writes outside typical data directories
NPS-10F4C12F27E0
The module writes generated handler/context/zod files to paths derived from user configuration (output.target, output.override.hono.handlers, etc.). This is expected behavior for a code generator, but writing arbitrary filesystem paths based on configuration warrants awareness. No evidence of writing to sensitive OS/credential locations.
Optional peer dependency fallback
NPS-CA15AF04C574
When 'typescript' is unavailable, smart/full strategies silently fall back to skip, leaving existing handler files unchanged. This is documented and benign.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.mjs | medium | The file is a legitimate orval code-generation module for Hono handlers; it performs expected filesystem reads/writes and lazily imports the optional 'typescript' parser, with no signs of data exfiltration, credential harvesting, shell execution, or obfuscated payloads. |
| dist/zValidator.ts | safe | No malicious patterns detected; the code is a legitimate Hono zod-validator middleware wrapper with no exfiltration, obfuscation, or suspicious behavior. |
Scanned versions of @orval/hono
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 8.39.0 | Needs review | 2 | Oct 6, 2026 |
Frequently asked questions
Is @orval/hono safe to use?
No confirmed malware was found in @orval/hono@8.39.0, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does @orval/hono contain malware?
No malware was identified in @orval/hono@8.39.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @orval/hono checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @orval/hono together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @orval/hono@8.39.0, cost nothing.