# @parcel/watcher@2.5.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:27.000Z
- Files reviewed: 3
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/@parcel/watcher
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @parcel/watcher@2.5.6 on Oct 6, 2026. An AI review of 3 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] top-level code execution on import

Finding ID: `NPS-01F1935BF727`

File: `index.js:1`

Module-level code runs require() calls and libc detection at import time. This is expected for native binding resolution in a Node.js addon package and does not involve filesystem manipulation, process spawning, network activity, or credential access.

### [low] dynamic module loading

Finding ID: `NPS-801E8B4F1A57`

File: `index.js:14`

The code uses require() with a computed variable 'name' derived from process.platform and process.arch, plus optional libc detection, to load a platform-specific native binding. This is a standard pattern for native addon packages and not a malicious obfuscation or external input vector.

### [low] Install-time/build-time execution

Finding ID: `NPS-73F21555C002`

File: `scripts/build-from-source.js:5`

The script executes automatically when required/imported if the environment variable npm_config_build_from_source is set to 'true'. It then runs node-gyp rebuild, which compiles native code. This is expected for a build helper script, but native compilation can execute arbitrary build steps (e.g., binding.gyp) if the package's build configuration were malicious. In this file alone, no malicious payload is present.

### [low] Process spawning with shell enabled

Finding ID: `NPS-AA1DEC3F3D33`

File: `scripts/build-from-source.js:11`

The script spawns 'node-gyp' with shell: true. While currently using a hardcoded command, enabling shell increases risk if the command or arguments were ever influenced by external input. In this specific case, the command and arguments are static, so exploitability is low, but it is still a code-quality/security hardening concern.

## Files reviewed

- `scripts/build-from-source.js` (medium): The script is a benign node-gyp build helper, but uses shell:true and runs at import time under an environment-variable condition, which are minor hardening concerns rather than active malicious behavior.
- `index.js` (safe): The file is a benign native binding loader for @parcel/watcher with no malicious patterns, exfiltration, credential harvesting, or process/network abuse.
- `wrapper.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
