Summary
Togoder Security scanned the npm package @parcel/watcher@2.5.6 on Oct 6, 2026. An AI review of 3 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
top-level code execution on import
NPS-01F1935BF727
Module-level code runs require() calls and libc detection at import time. This is expected for native binding resolution in a Node.js addon package and does not involve filesystem manipulation, process spawning, network activity, or credential access.
dynamic module loading
NPS-801E8B4F1A57
The code uses require() with a computed variable 'name' derived from process.platform and process.arch, plus optional libc detection, to load a platform-specific native binding. This is a standard pattern for native addon packages and not a malicious obfuscation or external input vector.
Install-time/build-time execution
NPS-73F21555C002
The script executes automatically when required/imported if the environment variable npm_config_build_from_source is set to 'true'. It then runs node-gyp rebuild, which compiles native code. This is expected for a build helper script, but native compilation can execute arbitrary build steps (e.g., binding.gyp) if the package's build configuration were malicious. In this file alone, no malicious payload is present.
Process spawning with shell enabled
NPS-AA1DEC3F3D33
The script spawns 'node-gyp' with shell: true. While currently using a hardcoded command, enabling shell increases risk if the command or arguments were ever influenced by external input. In this specific case, the command and arguments are static, so exploitability is low, but it is still a code-quality/security hardening concern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| scripts/build-from-source.js | medium | The script is a benign node-gyp build helper, but uses shell:true and runs at import time under an environment-variable condition, which are minor hardening concerns rather than active malicious behavior. |
| index.js | safe | The file is a benign native binding loader for @parcel/watcher with no malicious patterns, exfiltration, credential harvesting, or process/network abuse. |
| wrapper.js | safe | No malicious patterns detected |
Frequently asked questions
Is @parcel/watcher safe to use?
No confirmed malware was found in @parcel/watcher@2.5.6, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does @parcel/watcher contain malware?
No malware was identified in @parcel/watcher@2.5.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @parcel/watcher checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @parcel/watcher together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @parcel/watcher@2.5.6, cost nothing.