Togoder security

npm package security report

@swc/helpers npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.5.23 Files reviewed 328 Size 227.0 KB Scanned

Summary

Togoder Security scanned the npm package @swc/helpers@0.5.23 on Oct 6, 2026. An AI review of 328 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

dynamic code execution or object construction

NPS-CBDA8B107A5C

The function _possible_constructor_return returns the 'call' object if it is an object or function. This is a standard JavaScript pattern used in Babel-compiled classes to allow constructors to return a different object. However, returning an externally provided object can be exploited if 'call' is manipulated, potentially leading to prototype pollution or unexpected object behavior. The pattern itself is not inherently malicious but requires careful handling to avoid security issues.

esm/_possible_constructor_return.js:6
low

Prototype pollution potential

NPS-BE3DE4F6437C

The function uses Object.setPrototypeOf or a fallback that assigns to __proto__. This is a standard Babel helper for transpiling ES6 classes and is not inherently malicious, but if misused with untrusted input it could enable prototype pollution. No malicious behavior is present.

esm/_set_prototype_of.js:2
low

File system manipulation

NPS-717876AC4A6F

The build script removes generated directories (cjs, _, src) and writes new files within the package root. This is typical for a build process and not malicious.

scripts/build.js
low

Spawning processes

NPS-79D3D03FF8E2

The script executes external commands 'dprint fmt' via zx. This is a legitimate formatting step in the build process, not a backdoor.

scripts/build.js

Files reviewed

FileVerdictWhat the reviewer saw
esm/_possible_constructor_return.js medium The code is a standard Babel helper function for class constructor return values; it does not contain malicious patterns but exhibits a low-risk behavior of returning externally influenced objects.
cjs/_apply_decorated_descriptor.cjs safe This is a standard Babel helper function for applying decorators; no malicious patterns detected.
cjs/_apply_decs_2203_r.cjs safe This is a standard Babel helper for implementing decorators (applyDecs2203) with no malicious patterns, no network/file/process access, and no dynamic code execution.
cjs/_apply_decs_2311.cjs safe No malicious patterns detected; the file is a legitimate Babel helper for applying decorators.
cjs/_array_like_to_array.cjs safe No malicious patterns detected
cjs/_array_with_holes.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_array_without_holes.cjs safe No malicious patterns detected
cjs/_assert_this_initialized.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_async_generator.cjs safe No malicious patterns detected; the code is a standard Babel runtime helper for async generator control flow.
cjs/_async_generator_delegate.cjs safe No malicious patterns detected
cjs/_async_iterator.cjs safe The code implements standard async iterator polyfill functionality (Symbol.asyncIterator and Symbol.iterator handling) with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network requests, or file system manipulation.
cjs/_async_to_generator.cjs safe No malicious patterns detected; this is a standard Babel helper for converting async functions to generator-based Promise chains.
cjs/_await_async_generator.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_await_value.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_call_super.cjs safe This is a standard Babel runtime helper for calling super constructors; it contains no malicious patterns, network access, file system manipulation, or dynamic code execution.
cjs/_check_private_redeclaration.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_apply_descriptor_destructure.cjs safe No malicious patterns detected
cjs/_class_apply_descriptor_get.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_apply_descriptor_set.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_apply_descriptor_update.cjs safe No malicious patterns detected; the file contains a standard Babel helper for class private field descriptor updates with no network, filesystem, process, eval, or credential access.
cjs/_class_call_check.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_check_private_static_access.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_check_private_static_field_descriptor.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_extract_field_descriptor.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_name_tdz_error.cjs safe No malicious patterns detected
Show 303 more files
FileVerdictWhat the reviewer saw
cjs/_class_private_field_destructure.cjs safe No malicious patterns detected; the file is a standard Babel helper for private field destructuring with only local module imports and no execution, network, or filesystem activity.
cjs/_class_private_field_get.cjs safe No malicious patterns detected in this Babel helper module for private class field access.
cjs/_class_private_field_init.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_private_field_loose_base.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_private_field_loose_key.cjs safe No malicious patterns detected
cjs/_class_private_field_set.cjs safe No malicious patterns detected
cjs/_class_private_field_update.cjs safe No malicious patterns detected
cjs/_class_private_method_get.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_private_method_init.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_class_private_method_set.cjs safe The file is a standard Babel runtime helper that throws a TypeError on private method reassignment and contains no malicious patterns.
cjs/_class_static_private_field_destructure.cjs safe No malicious patterns detected
cjs/_class_static_private_field_spec_get.cjs safe No malicious patterns detected
cjs/_class_static_private_field_spec_set.cjs safe No malicious patterns detected
cjs/_class_static_private_field_update.cjs safe This file is a legitimate Babel helper for private static field updates; it contains no malicious patterns, network activity, or dynamic code execution.
cjs/_class_static_private_method_get.cjs safe No malicious patterns detected
cjs/_construct.cjs safe No malicious patterns detected; the code is a standard Babel helper for Reflect.construct polyfilling.
cjs/_create_class.cjs safe No malicious patterns detected
cjs/_create_for_of_iterator_helper_loose.cjs safe No malicious patterns detected
cjs/_create_super.cjs safe No malicious patterns detected; this is a standard Babel helper implementing ES6 class inheritance via Reflect.construct.
cjs/_decorate.cjs safe This is a standard Babel helper for implementing JavaScript decorators with no malicious patterns, network activity, or dynamic code execution.
cjs/_defaults.cjs safe No malicious patterns detected
cjs/_define_enumerable_properties.cjs safe No malicious patterns detected; the file contains a benign utility function for defining enumerable properties.
cjs/_define_property.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_dispose.cjs safe No malicious patterns detected
cjs/_export_star.cjs safe No malicious patterns detected; the code is a standard utility for re-exporting module properties using getters.
cjs/_extends.cjs safe The file is a standard Babel/TypeScript helper implementing an Object.assign polyfill with no malicious behavior.
cjs/_get.cjs safe No malicious patterns detected; this is a standard Babel helper implementing ES6 Reflect.get with a legacy fallback.
cjs/_get_prototype_of.cjs safe No malicious patterns detected
cjs/_identity.cjs safe No malicious patterns detected
cjs/_inherits.cjs safe No malicious patterns detected; this is a standard Babel helper for implementing prototypal inheritance.
cjs/_inherits_loose.cjs safe No malicious patterns detected
cjs/_initializer_define_property.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_initializer_warning_helper.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_instanceof.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_interop_require_default.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_interop_require_wildcard.cjs safe No malicious patterns detected; the file is a standard Babel/TypeScript CommonJS interoperability helper that only manipulates in-memory objects and caches without network, filesystem, process, or dynamic execution behavior.
cjs/_is_native_function.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_is_native_reflect_construct.cjs safe No malicious patterns detected; the code only performs a feature detection for native Reflect.construct support.
cjs/_iterable_to_array.cjs safe No malicious patterns detected
cjs/_iterable_to_array_limit.cjs safe No malicious patterns detected
cjs/_iterable_to_array_limit_loose.cjs safe No malicious patterns detected; the file is a benign Babel helper for converting a limited iterable to an array.
cjs/_jsx.cjs safe This is a standard React JSX runtime helper with no malicious patterns, network calls, or suspicious behavior.
cjs/_new_arrow_check.cjs safe No malicious patterns detected
cjs/_non_iterable_rest.cjs safe No malicious patterns detected; the file contains a benign Babel helper that throws a TypeError for non-iterable rest destructuring.
cjs/_non_iterable_spread.cjs safe No malicious patterns detected; the file only defines a helper function that throws a TypeError for invalid spread attempts.
cjs/_object_destructuring_empty.cjs safe No malicious patterns detected; the file contains a simple, benign destructuring helper function.
cjs/_object_spread.cjs safe No malicious patterns detected
cjs/_object_spread_props.cjs safe No malicious patterns detected; the code is a standard Babel helper for object spread property copying.
cjs/_object_without_properties.cjs safe No malicious patterns detected; the file is a legitimate Babel helper for copying object properties while excluding specified keys.
cjs/_object_without_properties_loose.cjs safe No malicious patterns detected
cjs/_overload_yield.cjs safe No malicious patterns detected; the file only defines and exports a simple constructor function.
cjs/_possible_constructor_return.cjs safe No malicious patterns detected
cjs/_read_only_error.cjs safe No malicious patterns detected
cjs/_set.cjs safe No malicious patterns detected
cjs/_set_prototype_of.cjs safe No malicious patterns detected
cjs/_skip_first_generator_next.cjs safe The file contains a trivial generator-skipping utility with no network, filesystem, process, or obfuscation behavior.
cjs/_sliced_to_array.cjs safe No malicious patterns detected; the file is a standard Babel helper for array destructuring.
cjs/_sliced_to_array_loose.cjs safe No malicious patterns detected; the file is a standard Babel helper for loose array destructuring with only module imports and no network, filesystem, process, or dynamic code execution.
cjs/_super_prop_base.cjs safe No malicious patterns detected
cjs/_tagged_template_literal.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_tagged_template_literal_loose.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_throw.cjs safe No malicious patterns detected; the file only exports a trivial helper function that rethrows its argument.
cjs/_to_array.cjs safe No malicious patterns detected; this is a standard Babel helper function that converts values to arrays using only local module imports.
cjs/_to_consumable_array.cjs safe This is a standard Babel transpilation helper for converting iterables to arrays with no malicious patterns, network activity, or code execution.
cjs/_to_primitive.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_to_property_key.cjs safe No malicious patterns detected
cjs/_ts_add_disposable_resource.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_ts_decorate.cjs safe No malicious patterns detected
cjs/_ts_dispose_resources.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_ts_generator.cjs safe No malicious patterns detected
cjs/_ts_metadata.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_ts_param.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_ts_rewrite_relative_import_extension.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_ts_values.cjs safe Cleared by Jev triage; no further analysis needed
cjs/_type_of.cjs safe Code only implements a standard typeof helper with no suspicious behavior.
cjs/_unsupported_iterable_to_array.cjs safe No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays.
cjs/_update.cjs safe No malicious patterns detected
cjs/_using.cjs safe No malicious patterns detected; this is a legitimate Babel helper for 'using' declarations with resource disposal.
cjs/_using_ctx.cjs safe No malicious patterns detected; the file is a legitimate helper for implementing JavaScript using/await using declarations with proper resource disposal and error handling.
cjs/_wrap_async_generator.cjs safe No malicious patterns detected; the code is a standard Babel async generator wrapper.
cjs/_wrap_native_super.cjs safe No malicious patterns detected; this is a standard Babel helper for wrapping native superclass constructors with no network, filesystem, process, or dynamic code execution behavior.
cjs/_wrap_reg_exp.cjs safe No malicious patterns detected; the code implements a RegExp wrapper with named group extraction and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behaviors.
cjs/_write_only_error.cjs safe No malicious patterns detected; the code is a simple utility function that throws a TypeError for write-only properties.
cjs/index.cjs safe No malicious patterns detected; the file is an auto-generated CommonJS barrel file that lazily re-exports Babel runtime helpers via relative requires.
esm/_apply_decorated_descriptor.js safe This is a legitimate Babel/TypeScript-style helper for applying decorators; the concatenated property names ('keys', 'defineProperty') are a known obfuscation-avoidance technique used by transpilers, not malicious, and no exfiltration, credential harvesting, dynamic execution, or install-time code is present.
esm/_apply_decs_2203_r.js safe No malicious patterns detected; this is a legitimate Babel decorators helper with no dynamic code execution, network access, or file system manipulation.
esm/_apply_decs_2311.js safe This is a standard Babel helper for applying decorators, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
esm/_array_like_to_array.js safe No malicious patterns detected; the code is a simple Babel-style helper that safely copies array-like objects.
esm/_array_with_holes.js safe No malicious patterns detected
esm/_array_without_holes.js safe No malicious patterns detected
esm/_assert_this_initialized.js safe No malicious patterns detected
esm/_async_generator.js safe No malicious patterns detected; this is a standard async generator runtime helper with no network, filesystem, process, or dynamic execution behavior.
esm/_async_generator_delegate.js safe No malicious patterns detected; this is a standard Babel helper for async generator delegation.
esm/_async_iterator.js safe This is a standard Babel/rollup-generated helper for async iterator polyfilling with no malicious patterns detected.
esm/_async_to_generator.js safe No malicious patterns detected; the file is a standard Babel async-to-generator helper with no external I/O, dynamic code execution, or credential access.
esm/_await_async_generator.js safe No malicious patterns detected
esm/_await_value.js safe Cleared by Jev triage; no further analysis needed
esm/_call_super.js safe This is a standard Babel helper for implementing ES6 class inheritance, with no malicious patterns detected.
esm/_check_private_redeclaration.js safe Cleared by Jev triage; no further analysis needed
esm/_class_apply_descriptor_destructure.js safe No malicious patterns detected
esm/_class_apply_descriptor_get.js safe Cleared by Jev triage; no further analysis needed
esm/_class_apply_descriptor_set.js safe Cleared by Jev triage; no further analysis needed
esm/_class_apply_descriptor_update.js safe No malicious patterns detected; the code is a standard Babel/TypeScript helper for handling private class field descriptors.
esm/_class_call_check.js safe No malicious patterns detected
esm/_class_check_private_static_access.js safe Cleared by Jev triage; no further analysis needed
esm/_class_check_private_static_field_descriptor.js safe Cleared by Jev triage; no further analysis needed
esm/_class_extract_field_descriptor.js safe Cleared by Jev triage; no further analysis needed
esm/_class_name_tdz_error.js safe No malicious patterns detected
esm/_class_private_field_destructure.js safe No malicious patterns detected
esm/_class_private_field_get.js safe No malicious patterns detected; the file is a simple Babel/TypeScript helper for private class field access.
esm/_class_private_field_init.js safe Cleared by Jev triage; no further analysis needed
esm/_class_private_field_loose_base.js safe Cleared by Jev triage; no further analysis needed
esm/_class_private_field_loose_key.js safe No malicious patterns detected
esm/_class_private_field_set.js safe No malicious patterns detected
esm/_class_private_field_update.js safe No malicious patterns detected
esm/_class_private_method_get.js safe No malicious patterns detected; the code is a standard Babel/TypeScript helper for accessing private class methods.
esm/_class_private_method_init.js safe Cleared by Jev triage; no further analysis needed
esm/_class_private_method_set.js safe No malicious patterns detected; the file only defines a helper that throws a TypeError when private methods are reassigned, which is standard Babel transpilation output.
esm/_class_static_private_field_destructure.js safe No malicious patterns detected
esm/_class_static_private_field_spec_get.js safe No malicious patterns detected
esm/_class_static_private_field_spec_set.js safe No malicious patterns detected
esm/_class_static_private_field_update.js safe This is a standard Babel helper function for private static field updates with no malicious patterns detected.
esm/_class_static_private_method_get.js safe No malicious patterns detected; the file is a standard Babel helper for private static method access.
esm/_construct.js safe This is a standard Babel helper for ES6 Reflect.construct with no malicious patterns.
esm/_create_class.js safe No malicious patterns detected; this is a standard Babel helper for defining class properties.
esm/_create_for_of_iterator_helper_loose.js safe No malicious patterns detected
esm/_create_super.js safe No malicious patterns detected
esm/_decorate.js safe This is a standard Babel/TypeScript decorator transformation helper with no malicious patterns, network calls, process spawning, or credential access.
esm/_defaults.js safe No malicious patterns detected
esm/_define_enumerable_properties.js safe No malicious patterns detected; the code is a standard Babel helper for defining enumerable properties.
esm/_define_property.js safe Cleared by Jev triage; no further analysis needed
esm/_dispose.js safe The code implements a standard polyfill for the Explicit Resource Management 'dispose' helper (SuppressedError and resource cleanup) with no malicious patterns such as data exfiltration, environment harvesting, dynamic code execution, or network activity.
esm/_export_star.js safe No malicious patterns detected; the code is a standard ES module helper for re-exporting properties with lazy getters.
esm/_extends.js safe This is a standard Babel helper function for Object.assign polyfill with no malicious patterns.
esm/_get.js safe No malicious patterns detected; the code is a standard Babel helper for accessing superclass properties and shows no signs of exfiltration, obfuscation, or unauthorized system access.
esm/_get_prototype_of.js safe No malicious patterns detected; the code is a standard Babel helper for retrieving object prototypes.
esm/_identity.js safe Cleared by Jev triage; no further analysis needed
esm/_inherits.js safe No malicious patterns detected
esm/_inherits_loose.js safe This is a standard Babel helper function for loose prototypal inheritance with no malicious patterns.
esm/_initializer_define_property.js safe Cleared by Jev triage; no further analysis needed
esm/_initializer_warning_helper.js safe Cleared by Jev triage; no further analysis needed
esm/_instanceof.js safe No malicious patterns detected; this is a standard SWC helper implementing instanceof with Symbol.hasInstance support.
esm/_interop_require_default.js safe No malicious patterns detected; this is a standard ES module interop helper function.
esm/_interop_require_wildcard.js safe No malicious patterns detected; the code is a standard Babel/TypeScript interop helper for wildcard require with WeakMap caching.
esm/_is_native_function.js safe Cleared by Jev triage; no further analysis needed
esm/_is_native_reflect_construct.js safe Cleared by Jev triage; no further analysis needed
esm/_iterable_to_array.js safe No malicious patterns detected
esm/_iterable_to_array_limit.js safe This is a standard Babel helper function for converting a limited iterable to an array, with no malicious patterns detected.
esm/_iterable_to_array_limit_loose.js safe No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays with a length limit.
esm/_jsx.js safe No malicious patterns detected; this is a standard React JSX runtime helper with no network, filesystem, process, or dynamic execution behavior.
esm/_new_arrow_check.js safe No malicious patterns detected
esm/_non_iterable_rest.js safe No malicious patterns detected
esm/_non_iterable_spread.js safe Cleared by Jev triage; no further analysis needed
esm/_object_destructuring_empty.js safe No malicious patterns detected; the file only contains a small helper that throws on null/undefined destructuring.
esm/_object_spread.js safe No malicious patterns detected; the code is a standard Babel helper implementing object spread semantics.
esm/_object_spread_props.js safe No malicious patterns detected; the code is a standard Babel-style object spread helper with no network, filesystem, process, or dynamic execution behavior.
esm/_object_without_properties.js safe This is a standard utility function that creates a shallow copy of an object excluding specified keys, with no network, filesystem, process execution, or credential-related behavior.
esm/_object_without_properties_loose.js safe This is a standard Babel helper function for creating object copies excluding specified properties, with no malicious patterns detected.
esm/_overload_yield.js safe The file defines a trivial helper class for wrapping yield values and exports it; no malicious patterns or risky behaviors are present.
esm/_read_only_error.js safe No malicious patterns detected
esm/_set.js safe No malicious patterns detected
esm/_set_prototype_of.js safe This is a standard Babel helper for setting object prototypes; no malicious patterns detected.
esm/_skip_first_generator_next.js safe No malicious patterns detected
esm/_sliced_to_array.js safe No malicious patterns detected; this is a standard Babel helper function for ES module interop.
esm/_sliced_to_array_loose.js safe No malicious patterns detected; the file is a standard Babel helper for loose array destructuring.
esm/_super_prop_base.js safe No malicious patterns detected
esm/_tagged_template_literal.js safe Cleared by Jev triage; no further analysis needed
esm/_tagged_template_literal_loose.js safe No malicious patterns detected
esm/_throw.js safe No malicious patterns detected
esm/_to_array.js safe This is a standard Babel helper function that converts iterables to arrays with no malicious patterns detected.
esm/_to_consumable_array.js safe The file is a standard Babel helper for converting iterables to arrays and contains no malicious patterns.
esm/_to_primitive.js safe No malicious patterns detected; the code is a standard JavaScript helper for converting objects to primitive values, with no network, filesystem, process, or obfuscation concerns.
esm/_to_property_key.js safe No malicious patterns detected
esm/_ts_add_disposable_resource.js safe No malicious patterns detected; this is a benign TypeScript helper re-export from tslib.
esm/_ts_decorate.js safe No malicious patterns detected
esm/_ts_dispose_resources.js safe No malicious patterns detected
esm/_ts_generator.js safe This is a standard TypeScript/JavaScript generator runtime helper with no malicious patterns detected.
esm/_ts_metadata.js safe The file simply re-exports the __metadata helper from the standard tslib package with no malicious patterns.
esm/_ts_param.js safe No malicious patterns detected
esm/_ts_rewrite_relative_import_extension.js safe No malicious patterns detected
esm/_ts_values.js safe No malicious patterns detected
esm/_type_of.js safe The file is a standard @swc/helpers typeof utility with no malicious patterns, network access, process spawning, or dynamic code execution.
esm/_unsupported_iterable_to_array.js safe No malicious patterns detected
esm/_update.js safe No malicious patterns detected; the file is a simple utility that delegates property access to _get and _set helper functions.
esm/_using.js safe Cleared by Jev triage; no further analysis needed
esm/_using_ctx.js safe This is a standard Babel helper for the JavaScript 'using' declarations (explicit resource management) proposal, containing no malicious patterns, network access, file system operations, or dynamic code execution.
esm/_wrap_async_generator.js safe Cleared by Jev triage; no further analysis needed
esm/_wrap_native_super.js safe No malicious patterns detected; the code is a standard Babel helper for wrapping native superclasses, with no external network, filesystem, process, or dynamic code execution behaviors.
esm/_wrap_reg_exp.js safe No malicious patterns detected; the code is a Babel helper for wrapping RegExp objects to support custom groups and source properties.
esm/_write_only_error.js safe No malicious patterns detected
esm/index.js safe This file is a standard Babel runtime re-export barrel with static, relative-path exports and no executable or suspicious code.
scripts/ast_grep.js safe No malicious patterns detected; the code is a legitimate AST-based build script that transforms ESM to CJS.
scripts/build.js safe The build script is a standard development utility that generates package exports and runs formatting; no malicious patterns were found.
scripts/errors.js safe Cleared by Jev triage; no further analysis needed
scripts/utils.js safe Cleared by Jev triage; no further analysis needed
src/_apply_decorated_descriptor.mjs safe Cleared by Jev triage; no further analysis needed
src/_apply_decs_2203_r.mjs safe Cleared by Jev triage; no further analysis needed
src/_apply_decs_2311.mjs safe Cleared by Jev triage; no further analysis needed
src/_array_like_to_array.mjs safe Cleared by Jev triage; no further analysis needed
src/_array_with_holes.mjs safe Cleared by Jev triage; no further analysis needed
src/_array_without_holes.mjs safe Cleared by Jev triage; no further analysis needed
src/_assert_this_initialized.mjs safe Cleared by Jev triage; no further analysis needed
src/_async_generator.mjs safe Cleared by Jev triage; no further analysis needed
src/_async_generator_delegate.mjs safe Cleared by Jev triage; no further analysis needed
src/_async_iterator.mjs safe Cleared by Jev triage; no further analysis needed
src/_async_to_generator.mjs safe Cleared by Jev triage; no further analysis needed
src/_await_async_generator.mjs safe Cleared by Jev triage; no further analysis needed
src/_await_value.mjs safe Cleared by Jev triage; no further analysis needed
src/_call_super.mjs safe Cleared by Jev triage; no further analysis needed
src/_check_private_redeclaration.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_apply_descriptor_destructure.mjs safe This file is a simple re-export statement with no executable logic or malicious patterns.
src/_class_apply_descriptor_get.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_apply_descriptor_set.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_apply_descriptor_update.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_call_check.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_check_private_static_access.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_check_private_static_field_descriptor.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_extract_field_descriptor.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_name_tdz_error.mjs safe No malicious patterns detected
src/_class_private_field_destructure.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_field_get.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_field_init.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_field_loose_base.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_field_loose_key.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_field_set.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_field_update.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_method_get.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_private_method_init.mjs safe No malicious patterns detected
src/_class_private_method_set.mjs safe No malicious patterns detected
src/_class_static_private_field_destructure.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_static_private_field_spec_get.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_static_private_field_spec_set.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_static_private_field_update.mjs safe Cleared by Jev triage; no further analysis needed
src/_class_static_private_method_get.mjs safe Cleared by Jev triage; no further analysis needed
src/_construct.mjs safe Cleared by Jev triage; no further analysis needed
src/_create_class.mjs safe Cleared by Jev triage; no further analysis needed
src/_create_for_of_iterator_helper_loose.mjs safe Cleared by Jev triage; no further analysis needed
src/_create_super.mjs safe Cleared by Jev triage; no further analysis needed
src/_decorate.mjs safe Cleared by Jev triage; no further analysis needed
src/_defaults.mjs safe Cleared by Jev triage; no further analysis needed
src/_define_enumerable_properties.mjs safe Cleared by Jev triage; no further analysis needed
src/_define_property.mjs safe Cleared by Jev triage; no further analysis needed
src/_dispose.mjs safe Cleared by Jev triage; no further analysis needed
src/_export_star.mjs safe No malicious patterns detected
src/_extends.mjs safe Cleared by Jev triage; no further analysis needed
src/_get.mjs safe Cleared by Jev triage; no further analysis needed
src/_get_prototype_of.mjs safe Cleared by Jev triage; no further analysis needed
src/_identity.mjs safe Cleared by Jev triage; no further analysis needed
src/_inherits.mjs safe Cleared by Jev triage; no further analysis needed
src/_inherits_loose.mjs safe Cleared by Jev triage; no further analysis needed
src/_initializer_define_property.mjs safe Cleared by Jev triage; no further analysis needed
src/_initializer_warning_helper.mjs safe Cleared by Jev triage; no further analysis needed
src/_instanceof.mjs safe Cleared by Jev triage; no further analysis needed
src/_interop_require_default.mjs safe Cleared by Jev triage; no further analysis needed
src/_interop_require_wildcard.mjs safe Cleared by Jev triage; no further analysis needed
src/_is_native_function.mjs safe Cleared by Jev triage; no further analysis needed
src/_is_native_reflect_construct.mjs safe Cleared by Jev triage; no further analysis needed
src/_iterable_to_array.mjs safe Cleared by Jev triage; no further analysis needed
src/_iterable_to_array_limit.mjs safe No malicious patterns detected
src/_iterable_to_array_limit_loose.mjs safe This file is a simple re-export that forwards the default export from another module without any malicious patterns or suspicious behavior.
src/_jsx.mjs safe Cleared by Jev triage; no further analysis needed
src/_new_arrow_check.mjs safe Cleared by Jev triage; no further analysis needed
src/_non_iterable_rest.mjs safe Cleared by Jev triage; no further analysis needed
src/_non_iterable_spread.mjs safe Cleared by Jev triage; no further analysis needed
src/_object_destructuring_empty.mjs safe This file is a simple re-export shim with no executable logic or malicious patterns.
src/_object_spread.mjs safe No malicious patterns detected
src/_object_spread_props.mjs safe No malicious patterns detected
src/_object_without_properties.mjs safe Cleared by Jev triage; no further analysis needed
src/_object_without_properties_loose.mjs safe No malicious patterns detected; the file is a simple re-export with no executable code or suspicious behavior.
src/_overload_yield.mjs safe Cleared by Jev triage; no further analysis needed
src/_possible_constructor_return.mjs safe Cleared by Jev triage; no further analysis needed
src/_read_only_error.mjs safe Cleared by Jev triage; no further analysis needed
src/_set.mjs safe Cleared by Jev triage; no further analysis needed
src/_set_prototype_of.mjs safe Cleared by Jev triage; no further analysis needed
src/_skip_first_generator_next.mjs safe Cleared by Jev triage; no further analysis needed
src/_sliced_to_array.mjs safe No malicious patterns detected
src/_sliced_to_array_loose.mjs safe Cleared by Jev triage; no further analysis needed
src/_super_prop_base.mjs safe Cleared by Jev triage; no further analysis needed
src/_tagged_template_literal.mjs safe Cleared by Jev triage; no further analysis needed
src/_tagged_template_literal_loose.mjs safe Cleared by Jev triage; no further analysis needed
src/_throw.mjs safe Cleared by Jev triage; no further analysis needed
src/_to_array.mjs safe Cleared by Jev triage; no further analysis needed
src/_to_consumable_array.mjs safe Cleared by Jev triage; no further analysis needed
src/_to_primitive.mjs safe Cleared by Jev triage; no further analysis needed
src/_to_property_key.mjs safe Cleared by Jev triage; no further analysis needed
src/_ts_add_disposable_resource.mjs safe The file only re-exports a default binding from another module with no executable top-level code or malicious patterns.
src/_ts_decorate.mjs safe Cleared by Jev triage; no further analysis needed
src/_ts_dispose_resources.mjs safe The file is a simple re-export statement with no malicious patterns detected.
src/_ts_generator.mjs safe Cleared by Jev triage; no further analysis needed
src/_ts_metadata.mjs safe Cleared by Jev triage; no further analysis needed
src/_ts_param.mjs safe Cleared by Jev triage; no further analysis needed
src/_ts_rewrite_relative_import_extension.mjs safe Cleared by Jev triage; no further analysis needed
src/_ts_values.mjs safe Cleared by Jev triage; no further analysis needed
src/_type_of.mjs safe Cleared by Jev triage; no further analysis needed
src/_unsupported_iterable_to_array.mjs safe Cleared by Jev triage; no further analysis needed
src/_update.mjs safe Cleared by Jev triage; no further analysis needed
src/_using.mjs safe Cleared by Jev triage; no further analysis needed
src/_using_ctx.mjs safe Cleared by Jev triage; no further analysis needed
src/_wrap_async_generator.mjs safe Cleared by Jev triage; no further analysis needed
src/_wrap_native_super.mjs safe Cleared by Jev triage; no further analysis needed
src/_wrap_reg_exp.mjs safe Cleared by Jev triage; no further analysis needed
src/_write_only_error.mjs safe Cleared by Jev triage; no further analysis needed
src/index.mjs safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of @swc/helpers are flagged high or critical. The latest scanned version, 0.5.23, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.5.50.5.23
VersionsVerdictCountRangeTop findings
0.5.23 Needs review 1 0.5.23
0.5.18 Not scanned 1 0.5.18
0.5.17 Needs review 1 0.5.17
0.5.5 Not scanned 1 0.5.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @swc/helpers

VersionVerdictFilesScanned
0.5.23 Needs review 328 Oct 6, 2026
0.5.17 Needs review 319 Oct 4, 2026

Frequently asked questions

Is @swc/helpers safe to use?

No confirmed malware was found in @swc/helpers@0.5.23, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does @swc/helpers contain malware?

No malware was identified in @swc/helpers@0.5.23 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @swc/helpers checked?

Togoder Security downloaded the published npm package and had an AI model read its 328 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @swc/helpers together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @swc/helpers@0.5.23, cost nothing.

Related security reports