Summary
Togoder Security scanned the npm package @semantic-release/github@12.0.5 on Oct 6, 2026. An AI review of 21 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
Import-time side effects
NPS-37E164D3FAA9
The module maintains a module-level mutable state variable 'verified' that is set during verifyConditions and used across publish/addChannel/success/fail. While this file itself does not execute network or filesystem operations at import time, the imported modules (./lib/verify.js, ./lib/publish.js, ./lib/add-channel.js, ./lib/success.js, ./lib/fail.js, ./lib/octokit.js) are not shown and could contain hidden side effects or malicious logic (credential harvesting, exfiltration, etc.). The code should be reviewed alongside those files.
GitHub token / credential access via Octokit
NPS-CBAD3C3D311A
The plugin conditionally injects an Octokit instance (SemanticReleaseOctokit) and passes it to verify/publish/addChannel/success/fail functions. Octokit instances typically carry GitHub authentication tokens (GH_TOKEN/GITHUB_TOKEN) from the environment. Because the downstream lib files are not provided, there is no visibility into whether these tokens are used only for intended GitHub API calls or potentially exfiltrated. This is a common vector for supply-chain token theft in CI/CD environments.
Configuration merge from other plugin configs
NPS-680692133F80
The verifyConditions function reads the 'publish' plugin configuration and copies fields (assets, successComment, failComment, failTitle, labels, assignees, discussionCategoryName) into pluginConfig. While this mirrors legitimate @semantic-release/github behavior, it allows one plugin's config to influence another's behavior, which could be abused in a compromised dependency chain to inject attacker-controlled values (e.g., labels, comments) into GitHub releases. This is not inherently malicious but warrants scrutiny in context.
Dynamic module loading via createRequire
NPS-5004A9F46138
Uses createRequire(import.meta.url) to load package.json at import time. While package.json is loaded from a relative path, createRequire enables arbitrary module resolution and loading which could be abused if the path were influenced. This pattern is common but worth noting.
Top-level code execution on import
NPS-9D1F87AD4614
Top-level statements read package.json and construct the Octokit plugin class at module load time. This is benign initialization but does execute on import.
Proxy agent configuration with user input
NPS-3F4054FB5CD2
Proxy agents (HttpProxyAgent, HttpsProxyAgent, ProxyAgent) are constructed from the options.proxy value passed by the caller. If options.proxy is attacker-controlled, requests could be redirected through arbitrary proxies, enabling MITM or data exfiltration. This is a legitimate feature for the package but requires the caller to validate proxy config.
Network requests with dynamic URLs
NPS-9D7D88BF439D
fetchWithDispatcher sends HTTP requests to caller-supplied URLs (baseUrl / githubApiUrl). This is expected functionality of a GitHub API client, but the dynamic URL construction via urljoin could allow requests to unintended hosts if inputs are attacker-controlled.
unknown
NPS-D97596670BD0
The function reads sensitive environment variables such as GH_TOKEN, GITHUB_TOKEN and proxy settings. Although this is normal for a config resolver, it could be abused if the resolved config is later logged or sent elsewhere. No exfiltration is present in this file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | This file is the public entry point for what appears to be @semantic-release/github; no direct malicious patterns are present, but it delegates sensitive operations (GitHub API calls with auth tokens) to unreviewed lib/* modules and merges configuration from other plugin configs, so downstream files must be audited to rule out credential exfiltration or supply-chain abuse. |
| lib/octokit.js | medium | This is a legitimate GitHub API client wrapper (@semantic-release/github) with no obvious malicious patterns; minor concerns relate to dynamic require, proxy handling, and import-time initialization, all consistent with its intended purpose. |
| lib/resolve-config.js | medium | No malicious patterns detected; the file is a normal configuration resolver that reads environment variables but does not exfiltrate or execute untrusted code. |
| lib/add-channel.js | safe | No malicious patterns detected; the code is a legitimate semantic-release GitHub plugin that creates or updates GitHub releases using configured credentials. |
| lib/definitions/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/definitions/errors.js | safe | No malicious patterns detected; the file contains only error message definitions for a semantic-release plugin, using standard Node.js utilities with no network, credential, or process manipulation. |
| lib/definitions/retry.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/definitions/throttle.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/fail.js | safe | No malicious patterns detected; the code is a legitimate semantic-release GitHub plugin that creates issues on release failure. |
| lib/find-sr-issues.js | safe | No malicious patterns detected |
| lib/get-error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/get-fail-comment.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/get-release-links.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/get-success-comment.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/glob-assets.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/is-latest-release.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/is-prerelease.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/parse-github-url.js | safe | No malicious patterns detected |
| lib/publish.js | safe | No malicious patterns detected; this is a legitimate semantic-release GitHub plugin that publishes releases and uploads assets via the GitHub API. |
| lib/success.js | safe | No malicious patterns detected; the file is a standard semantic-release GitHub plugin that uses the provided Octokit instance for GitHub API calls and contains no exfiltration, credential harvesting, obfuscation, or shell execution. |
| lib/verify.js | safe | No malicious patterns detected; the file contains legitimate configuration validation and GitHub API verification logic for a semantic-release plugin. |
Frequently asked questions
Is @semantic-release/github safe to use?
No confirmed malware was found in @semantic-release/github@12.0.5, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @semantic-release/github contain malware?
No malware was identified in @semantic-release/github@12.0.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @semantic-release/github checked?
Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @semantic-release/github together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @semantic-release/github@12.0.5, cost nothing.