Togoder security

npm package security report

@parcel/watcher npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.5.6 Files reviewed 3 Size 3.3 KB Scanned

Summary

Togoder Security scanned the npm package @parcel/watcher@2.5.6 on Oct 6, 2026. An AI review of 3 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

top-level code execution on import

NPS-01F1935BF727

Module-level code runs require() calls and libc detection at import time. This is expected for native binding resolution in a Node.js addon package and does not involve filesystem manipulation, process spawning, network activity, or credential access.

index.js:1
low

dynamic module loading

NPS-801E8B4F1A57

The code uses require() with a computed variable 'name' derived from process.platform and process.arch, plus optional libc detection, to load a platform-specific native binding. This is a standard pattern for native addon packages and not a malicious obfuscation or external input vector.

index.js:14
low

Install-time/build-time execution

NPS-73F21555C002

The script executes automatically when required/imported if the environment variable npm_config_build_from_source is set to 'true'. It then runs node-gyp rebuild, which compiles native code. This is expected for a build helper script, but native compilation can execute arbitrary build steps (e.g., binding.gyp) if the package's build configuration were malicious. In this file alone, no malicious payload is present.

scripts/build-from-source.js:5
low

Process spawning with shell enabled

NPS-AA1DEC3F3D33

The script spawns 'node-gyp' with shell: true. While currently using a hardcoded command, enabling shell increases risk if the command or arguments were ever influenced by external input. In this specific case, the command and arguments are static, so exploitability is low, but it is still a code-quality/security hardening concern.

scripts/build-from-source.js:11

Files reviewed

FileVerdictWhat the reviewer saw
scripts/build-from-source.js medium The script is a benign node-gyp build helper, but uses shell:true and runs at import time under an environment-variable condition, which are minor hardening concerns rather than active malicious behavior.
index.js safe The file is a benign native binding loader for @parcel/watcher with no malicious patterns, exfiltration, credential harvesting, or process/network abuse.
wrapper.js safe No malicious patterns detected

Scanned versions of @parcel/watcher

VersionVerdictFilesScanned
2.5.6 Needs review 3 Oct 6, 2026

Frequently asked questions

Is @parcel/watcher safe to use?

No confirmed malware was found in @parcel/watcher@2.5.6, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does @parcel/watcher contain malware?

No malware was identified in @parcel/watcher@2.5.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @parcel/watcher checked?

Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @parcel/watcher together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @parcel/watcher@2.5.6, cost nothing.

Related security reports