Togoder security

npm package security report

@reduxjs/toolkit npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.11.2 Files reviewed 123 Size 1.4 MB Scanned

Summary

Togoder Security scanned the npm package @reduxjs/toolkit@2.11.2 on Oct 6, 2026. An AI review of 123 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Global object access

NPS-518116AB9C7E

The code accesses window.__REDUX_DEVTOOLS_EXTENSION_COMPOSE__ and window.__REDUX_DEVTOOLS_EXTENSION__ on the global window object. While this is the intended mechanism for Redux DevTools integration, it means that any script running on the page (including malicious browser extensions or cross-site scripting payloads) can hijack these hooks to intercept all dispatched actions and state changes, potentially leaking sensitive application data. This is a known and accepted risk for Redux DevTools, but is worth noting.

src/devtoolsExtension.ts
low

Dynamic endpoint injection

NPS-1A41EDA10246

injectEndpoints evaluates user-supplied endpoint definitions and assigns them to context.endpointDefinitions. This is the intended public API for RTK Query and is not hidden or obfuscated.

src/query/createApi.ts:460
low

Development-only logging

NPS-8483A2C1B450

The code uses process.env.NODE_ENV === 'development' checks to conditionally log errors and throw validation errors. This is standard debugging behavior, not credential harvesting or exfiltration.

src/query/createApi.ts:482

Files reviewed

FileVerdictWhat the reviewer saw
src/devtoolsExtension.ts medium This is the legitimate Redux DevTools extension integration file; it accesses global window hooks for DevTools, which is standard behavior but introduces a minor risk of DevTools hijacking.
dist/cjs/index.js safe The file is a standard CommonJS entry point that conditionally requires the production or development build based on NODE_ENV, with no malicious patterns detected.
dist/cjs/redux-toolkit.development.cjs safe This is the legitimate Redux Toolkit development build with no malicious patterns detected; all imports, exports, and logic are consistent with the official library.
dist/cjs/redux-toolkit.production.min.cjs safe No malicious patterns detected; the code is the official Redux Toolkit production build with expected Redux/Immer/Reselect usage and no data exfiltration, credential harvesting, obfuscation, backdoors, or suspicious network/process activity.
dist/query/cjs/index.js safe No malicious patterns detected
dist/query/cjs/rtk-query.production.min.cjs safe This is the minified production build of Redux Toolkit Query (rtk-query), a standard open-source state management library, with no malicious patterns detected.
dist/query/react/cjs/index.js safe No malicious patterns detected; this is a standard conditional module export based on NODE_ENV for the RTK Query React package.
dist/query/react/cjs/rtk-query-react.development.cjs safe The file is the standard Redux Toolkit Query React development bundle; it contains no data exfiltration, credential harvesting, obfuscation, dynamic code execution, or other malicious patterns.
dist/query/react/cjs/rtk-query-react.production.min.cjs safe This is the official RTK Query React production bundle containing only standard React/Redux logic with no malicious patterns detected.
dist/query/react/rtk-query-react.browser.mjs safe No malicious patterns detected; the file is a standard bundled RTK Query React integration module with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
dist/query/react/rtk-query-react.legacy-esm.js safe No malicious patterns detected; this is the official Redux Toolkit Query React integration with no suspicious behavior.
dist/query/react/rtk-query-react.modern.mjs safe No malicious patterns detected; this is the legitimate Redux Toolkit Query React integration module with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/query/rtk-query.browser.mjs safe This is a legitimate Redux Toolkit Query (RTK Query) library bundle with standard data fetching, caching, and retry logic; no malicious patterns detected.
dist/query/rtk-query.modern.mjs safe No malicious patterns detected; the code is the standard RTK Query library with no signs of exfiltration, obfuscation, or unauthorized behavior.
dist/react/cjs/index.js safe No malicious patterns detected; the file only conditionally re-exports production or development bundles based on NODE_ENV.
dist/react/cjs/redux-toolkit-react.development.cjs safe This is a standard Redux Toolkit React bindings build artifact with no malicious patterns, no network activity, no credential harvesting, and no dynamic code execution.
dist/react/cjs/redux-toolkit-react.production.min.cjs safe No malicious patterns detected; the code is a standard minified Redux Toolkit integration with React Redux.
dist/react/redux-toolkit-react.browser.mjs safe No malicious patterns detected
dist/react/redux-toolkit-react.legacy-esm.js safe No malicious patterns detected; the code is standard Redux Toolkit/React-Redux utility and re-export logic.
dist/react/redux-toolkit-react.modern.mjs safe The code is a legitimate Redux Toolkit dynamic middleware extension that re-exports Redux Toolkit and provides middleware creation utilities without any malicious patterns.
dist/redux-toolkit.browser.mjs safe No malicious patterns detected
dist/redux-toolkit.legacy-esm.js safe No malicious patterns detected; this is the standard Redux Toolkit library bundle with expected Redux/Immer/Reselect functionality and no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/redux-toolkit.modern.mjs safe This is the legitimate official Redux Toolkit library source code with no malicious patterns; it contains standard Redux state management logic, development-mode invariant checks, and no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/uncheckedindexed.ts safe Cleared by Jev triage; no further analysis needed
src/actionCreatorInvariantMiddleware.ts safe No malicious patterns detected; the code is a legitimate Redux Toolkit middleware for development-time warnings about dispatching action creators.
Show 98 more files
FileVerdictWhat the reviewer saw
src/autoBatchEnhancer.ts safe Cleared by Jev triage; no further analysis needed
src/combineSlices.ts safe This is a legitimate Redux Toolkit source file implementing reducer injection and selector proxying, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or install-time execution.
src/configureStore.ts safe No malicious patterns detected; the code is a standard Redux Toolkit configureStore implementation with only benign validation and store creation logic.
src/createAction.ts safe Cleared by Jev triage; no further analysis needed
src/createAsyncThunk.ts safe Cleared by Jev triage; no further analysis needed
src/createDraftSafeSelector.ts safe Cleared by Jev triage; no further analysis needed
src/createReducer.ts safe No malicious patterns detected; the file is a standard Redux Toolkit createReducer implementation with no network, filesystem, process, or dynamic code execution concerns.
src/createSlice.ts safe No malicious patterns detected; the code is a standard Redux Toolkit createSlice implementation with only benign development-time checks and no network, filesystem, process, or obfuscated behavior.
src/dynamicMiddleware/index.ts safe Cleared by Jev triage; no further analysis needed
src/dynamicMiddleware/react/index.ts safe Cleared by Jev triage; no further analysis needed
src/dynamicMiddleware/types.ts safe Cleared by Jev triage; no further analysis needed
src/entities/create_adapter.ts safe Cleared by Jev triage; no further analysis needed
src/entities/entity_state.ts safe Cleared by Jev triage; no further analysis needed
src/entities/index.ts safe Cleared by Jev triage; no further analysis needed
src/entities/models.ts safe Cleared by Jev triage; no further analysis needed
src/entities/sorted_state_adapter.ts safe Cleared by Jev triage; no further analysis needed
src/entities/state_adapter.ts safe Cleared by Jev triage; no further analysis needed
src/entities/state_selectors.ts safe Cleared by Jev triage; no further analysis needed
src/entities/unsorted_state_adapter.ts safe Cleared by Jev triage; no further analysis needed
src/entities/utils.ts safe No malicious patterns detected; the file contains pure Redux Toolkit entity utility functions with no network, filesystem, process, or dynamic code execution behavior.
src/formatProdErrorMessage.ts safe Cleared by Jev triage; no further analysis needed
src/getDefaultEnhancers.ts safe Cleared by Jev triage; no further analysis needed
src/getDefaultMiddleware.ts safe No malicious patterns detected; the code is a standard Redux Toolkit middleware configuration utility with no exfiltration, dynamic execution, or process spawning.
src/immerImports.ts safe Cleared by Jev triage; no further analysis needed
src/immutableStateInvariantMiddleware.ts safe No malicious patterns detected; this is a legitimate Redux Toolkit immutable state invariant middleware that performs only in-memory state mutation tracking with no network, filesystem, process, or dynamic code execution activity.
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/listenerMiddleware/exceptions.ts safe Cleared by Jev triage; no further analysis needed
src/listenerMiddleware/index.ts safe Cleared by Jev triage; no further analysis needed
src/listenerMiddleware/task.ts safe Cleared by Jev triage; no further analysis needed
src/listenerMiddleware/types.ts safe Cleared by Jev triage; no further analysis needed
src/listenerMiddleware/utils.ts safe Cleared by Jev triage; no further analysis needed
src/mapBuilders.ts safe Cleared by Jev triage; no further analysis needed
src/matchers.ts safe Cleared by Jev triage; no further analysis needed
src/nanoid.ts safe Cleared by Jev triage; no further analysis needed
src/query/HandledError.ts safe Cleared by Jev triage; no further analysis needed
src/query/apiTypes.ts safe Cleared by Jev triage; no further analysis needed
src/query/baseQueryTypes.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/apiState.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildInitiate.ts safe No malicious patterns detected; the code is a standard Redux Toolkit Query initiate builder with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file/process activity.
src/query/core/buildMiddleware/batchActions.ts safe This is a standard Redux Toolkit Query middleware for batching subscription actions; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity were detected.
src/query/core/buildMiddleware/cacheCollection.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildMiddleware/cacheLifecycle.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildMiddleware/devMiddleware.ts safe No malicious patterns detected; the code only performs development-mode logging and API middleware registration checks.
src/query/core/buildMiddleware/index.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildMiddleware/invalidationByTags.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildMiddleware/polling.ts safe No malicious patterns detected; the code is a legitimate polling middleware implementation for RTK Query with no network, filesystem, process, or credential access.
src/query/core/buildMiddleware/queryLifecycle.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildMiddleware/types.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildMiddleware/windowEventHandling.ts safe No malicious patterns detected; the code is a standard Redux Toolkit Query window event handler that refetches queries on focus/online events.
src/query/core/buildSelectors.ts safe No malicious patterns detected
src/query/core/buildSlice.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/buildThunks.ts safe No malicious patterns detected
src/query/core/index.ts safe No malicious patterns detected
src/query/core/module.ts safe No malicious patterns detected; this is the legitimate RTK Query core module with only type imports, internal state setup, and no network, filesystem, process, or dynamic code execution.
src/query/core/rtkImports.ts safe Cleared by Jev triage; no further analysis needed
src/query/core/setupListeners.ts safe Cleared by Jev triage; no further analysis needed
src/query/createApi.ts safe No malicious patterns detected; the file implements RTK Query's createApi and only contains expected development-time logging and endpoint injection logic.
src/query/defaultSerializeQueryArgs.ts safe Cleared by Jev triage; no further analysis needed
src/query/endpointDefinitions.ts safe Cleared by Jev triage; no further analysis needed
src/query/fakeBaseQuery.ts safe Cleared by Jev triage; no further analysis needed
src/query/fetchBaseQuery.ts safe No malicious patterns detected; this is a legitimate Redux Toolkit fetchBaseQuery implementation with standard fetch wrapper functionality.
src/query/index.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/ApiProvider.tsx safe Cleared by Jev triage; no further analysis needed
src/query/react/buildHooks.ts safe This is the official Redux Toolkit Query React hooks build file containing only standard hook logic, type definitions, and Redux dispatch calls with no malicious patterns.
src/query/react/constants.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/index.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/module.ts safe No malicious patterns detected; the file is a legitimate Redux Toolkit Query React hooks module with no exfiltration, obfuscation, or dangerous side effects.
src/query/react/namedHooks.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/reactImports.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/reactReduxImports.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/rtkqImports.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/useSerializedStableValue.ts safe Cleared by Jev triage; no further analysis needed
src/query/react/useShallowStableValue.ts safe Cleared by Jev triage; no further analysis needed
src/query/retry.ts safe Cleared by Jev triage; no further analysis needed
src/query/standardSchema.ts safe Cleared by Jev triage; no further analysis needed
src/query/tsHelpers.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/capitalize.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/copyWithStructuralSharing.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/countObjectKeys.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/filterMap.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/getCurrent.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/getOrInsert.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/immerImports.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/index.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/isAbsoluteUrl.ts safe No malicious patterns detected
src/query/utils/isDocumentVisible.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/isNotNullish.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/isOnline.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/isValidUrl.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/joinUrls.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils/signals.ts safe Cleared by Jev triage; no further analysis needed
src/react/index.ts safe Cleared by Jev triage; no further analysis needed
src/reduxImports.ts safe Cleared by Jev triage; no further analysis needed
src/reselectImports.ts safe Cleared by Jev triage; no further analysis needed
src/serializableStateInvariantMiddleware.ts safe No malicious patterns detected; the code is a legitimate Redux Toolkit serializability-checking middleware with no network, filesystem, process, or obfuscation concerns.
src/tsHelpers.ts safe Cleared by Jev triage; no further analysis needed
src/uncheckedindexed.ts safe Cleared by Jev triage; no further analysis needed
src/utils.ts safe Cleared by Jev triage; no further analysis needed

Scanned versions of @reduxjs/toolkit

VersionVerdictFilesScanned
2.11.2 Needs review 123 Oct 6, 2026

Frequently asked questions

Is @reduxjs/toolkit safe to use?

No confirmed malware was found in @reduxjs/toolkit@2.11.2, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does @reduxjs/toolkit contain malware?

No malware was identified in @reduxjs/toolkit@2.11.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reduxjs/toolkit checked?

Togoder Security downloaded the published npm package and had an AI model read its 123 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reduxjs/toolkit together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reduxjs/toolkit@2.11.2, cost nothing.

Related security reports