Summary
Togoder Security scanned the npm package @semantic-release/commit-analyzer@13.0.1 on Oct 6, 2026. An AI review of 7 source files produced 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic module loading with external input
NPS-2F266E1AF388
The code dynamically constructs a module name from the user-supplied 'preset' parameter and imports it from either the package directory or the current working directory. While the dynamic import uses 'import-from-esm' rather than raw 'import()', this pattern allows loading arbitrary npm packages based on external configuration. An attacker controlling the preset value could potentially load a malicious package, though the preset is typically provided by the developer in semantic-release configuration.
Dynamic module loading with external input
NPS-6CFC89CA5893
The 'config' parameter allows loading an arbitrary npm package name from the current working directory. Similar to the preset case, this enables loading external modules based on configuration. In a supply chain attack scenario where the configuration is controlled by an attacker, this could be exploited to execute malicious code.
Dynamic module loading with external input
NPS-6FC8ABF8B49E
The function uses importFrom.silent() and importFrom() to dynamically import a module specified by the 'releaseRules' parameter, which can be a string. This allows loading arbitrary modules from the current working directory (cwd) or relative to the script's directory. If an attacker can control the 'releaseRules' configuration, they could load and execute a malicious module. This is a potential vector for code execution if the input is not properly trusted.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/load-parser-config.js | medium | The code dynamically imports npm packages based on configuration parameters, which is a legitimate feature of semantic-release plugins but presents a moderate risk if configuration is attacker-controlled. |
| lib/load-release-rules.js | medium | The code dynamically imports external modules based on configuration input, which could lead to arbitrary code execution if the input is untrusted, though no immediate malicious patterns were detected. |
| index.js | safe | No malicious patterns detected; the code is a standard semantic-release commit analyzer plugin with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| lib/analyze-commit.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compare-release-types.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/default-release-rules.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/default-release-types.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is @semantic-release/commit-analyzer safe to use?
No confirmed malware was found in @semantic-release/commit-analyzer@13.0.1, but the review flagged 3 medium severity findings for risky patterns worth checking before you rely on it.
Does @semantic-release/commit-analyzer contain malware?
No malware was identified in @semantic-release/commit-analyzer@13.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @semantic-release/commit-analyzer checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @semantic-release/commit-analyzer together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @semantic-release/commit-analyzer@13.0.1, cost nothing.