Summary
Togoder Security scanned the npm package @swc/helpers@0.5.23 on Oct 6, 2026. An AI review of 328 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
dynamic code execution or object construction
NPS-CBDA8B107A5C
The function _possible_constructor_return returns the 'call' object if it is an object or function. This is a standard JavaScript pattern used in Babel-compiled classes to allow constructors to return a different object. However, returning an externally provided object can be exploited if 'call' is manipulated, potentially leading to prototype pollution or unexpected object behavior. The pattern itself is not inherently malicious but requires careful handling to avoid security issues.
Prototype pollution potential
NPS-BE3DE4F6437C
The function uses Object.setPrototypeOf or a fallback that assigns to __proto__. This is a standard Babel helper for transpiling ES6 classes and is not inherently malicious, but if misused with untrusted input it could enable prototype pollution. No malicious behavior is present.
File system manipulation
NPS-717876AC4A6F
The build script removes generated directories (cjs, _, src) and writes new files within the package root. This is typical for a build process and not malicious.
Spawning processes
NPS-79D3D03FF8E2
The script executes external commands 'dprint fmt' via zx. This is a legitimate formatting step in the build process, not a backdoor.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/_possible_constructor_return.js | medium | The code is a standard Babel helper function for class constructor return values; it does not contain malicious patterns but exhibits a low-risk behavior of returning externally influenced objects. |
| cjs/_apply_decorated_descriptor.cjs | safe | This is a standard Babel helper function for applying decorators; no malicious patterns detected. |
| cjs/_apply_decs_2203_r.cjs | safe | This is a standard Babel helper for implementing decorators (applyDecs2203) with no malicious patterns, no network/file/process access, and no dynamic code execution. |
| cjs/_apply_decs_2311.cjs | safe | No malicious patterns detected; the file is a legitimate Babel helper for applying decorators. |
| cjs/_array_like_to_array.cjs | safe | No malicious patterns detected |
| cjs/_array_with_holes.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_array_without_holes.cjs | safe | No malicious patterns detected |
| cjs/_assert_this_initialized.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_async_generator.cjs | safe | No malicious patterns detected; the code is a standard Babel runtime helper for async generator control flow. |
| cjs/_async_generator_delegate.cjs | safe | No malicious patterns detected |
| cjs/_async_iterator.cjs | safe | The code implements standard async iterator polyfill functionality (Symbol.asyncIterator and Symbol.iterator handling) with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network requests, or file system manipulation. |
| cjs/_async_to_generator.cjs | safe | No malicious patterns detected; this is a standard Babel helper for converting async functions to generator-based Promise chains. |
| cjs/_await_async_generator.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_await_value.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_call_super.cjs | safe | This is a standard Babel runtime helper for calling super constructors; it contains no malicious patterns, network access, file system manipulation, or dynamic code execution. |
| cjs/_check_private_redeclaration.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_apply_descriptor_destructure.cjs | safe | No malicious patterns detected |
| cjs/_class_apply_descriptor_get.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_apply_descriptor_set.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_apply_descriptor_update.cjs | safe | No malicious patterns detected; the file contains a standard Babel helper for class private field descriptor updates with no network, filesystem, process, eval, or credential access. |
| cjs/_class_call_check.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_check_private_static_access.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_check_private_static_field_descriptor.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_extract_field_descriptor.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_name_tdz_error.cjs | safe | No malicious patterns detected |
Show 303 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| cjs/_class_private_field_destructure.cjs | safe | No malicious patterns detected; the file is a standard Babel helper for private field destructuring with only local module imports and no execution, network, or filesystem activity. |
| cjs/_class_private_field_get.cjs | safe | No malicious patterns detected in this Babel helper module for private class field access. |
| cjs/_class_private_field_init.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_private_field_loose_base.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_private_field_loose_key.cjs | safe | No malicious patterns detected |
| cjs/_class_private_field_set.cjs | safe | No malicious patterns detected |
| cjs/_class_private_field_update.cjs | safe | No malicious patterns detected |
| cjs/_class_private_method_get.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_private_method_init.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_class_private_method_set.cjs | safe | The file is a standard Babel runtime helper that throws a TypeError on private method reassignment and contains no malicious patterns. |
| cjs/_class_static_private_field_destructure.cjs | safe | No malicious patterns detected |
| cjs/_class_static_private_field_spec_get.cjs | safe | No malicious patterns detected |
| cjs/_class_static_private_field_spec_set.cjs | safe | No malicious patterns detected |
| cjs/_class_static_private_field_update.cjs | safe | This file is a legitimate Babel helper for private static field updates; it contains no malicious patterns, network activity, or dynamic code execution. |
| cjs/_class_static_private_method_get.cjs | safe | No malicious patterns detected |
| cjs/_construct.cjs | safe | No malicious patterns detected; the code is a standard Babel helper for Reflect.construct polyfilling. |
| cjs/_create_class.cjs | safe | No malicious patterns detected |
| cjs/_create_for_of_iterator_helper_loose.cjs | safe | No malicious patterns detected |
| cjs/_create_super.cjs | safe | No malicious patterns detected; this is a standard Babel helper implementing ES6 class inheritance via Reflect.construct. |
| cjs/_decorate.cjs | safe | This is a standard Babel helper for implementing JavaScript decorators with no malicious patterns, network activity, or dynamic code execution. |
| cjs/_defaults.cjs | safe | No malicious patterns detected |
| cjs/_define_enumerable_properties.cjs | safe | No malicious patterns detected; the file contains a benign utility function for defining enumerable properties. |
| cjs/_define_property.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_dispose.cjs | safe | No malicious patterns detected |
| cjs/_export_star.cjs | safe | No malicious patterns detected; the code is a standard utility for re-exporting module properties using getters. |
| cjs/_extends.cjs | safe | The file is a standard Babel/TypeScript helper implementing an Object.assign polyfill with no malicious behavior. |
| cjs/_get.cjs | safe | No malicious patterns detected; this is a standard Babel helper implementing ES6 Reflect.get with a legacy fallback. |
| cjs/_get_prototype_of.cjs | safe | No malicious patterns detected |
| cjs/_identity.cjs | safe | No malicious patterns detected |
| cjs/_inherits.cjs | safe | No malicious patterns detected; this is a standard Babel helper for implementing prototypal inheritance. |
| cjs/_inherits_loose.cjs | safe | No malicious patterns detected |
| cjs/_initializer_define_property.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_initializer_warning_helper.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_instanceof.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_interop_require_default.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_interop_require_wildcard.cjs | safe | No malicious patterns detected; the file is a standard Babel/TypeScript CommonJS interoperability helper that only manipulates in-memory objects and caches without network, filesystem, process, or dynamic execution behavior. |
| cjs/_is_native_function.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_is_native_reflect_construct.cjs | safe | No malicious patterns detected; the code only performs a feature detection for native Reflect.construct support. |
| cjs/_iterable_to_array.cjs | safe | No malicious patterns detected |
| cjs/_iterable_to_array_limit.cjs | safe | No malicious patterns detected |
| cjs/_iterable_to_array_limit_loose.cjs | safe | No malicious patterns detected; the file is a benign Babel helper for converting a limited iterable to an array. |
| cjs/_jsx.cjs | safe | This is a standard React JSX runtime helper with no malicious patterns, network calls, or suspicious behavior. |
| cjs/_new_arrow_check.cjs | safe | No malicious patterns detected |
| cjs/_non_iterable_rest.cjs | safe | No malicious patterns detected; the file contains a benign Babel helper that throws a TypeError for non-iterable rest destructuring. |
| cjs/_non_iterable_spread.cjs | safe | No malicious patterns detected; the file only defines a helper function that throws a TypeError for invalid spread attempts. |
| cjs/_object_destructuring_empty.cjs | safe | No malicious patterns detected; the file contains a simple, benign destructuring helper function. |
| cjs/_object_spread.cjs | safe | No malicious patterns detected |
| cjs/_object_spread_props.cjs | safe | No malicious patterns detected; the code is a standard Babel helper for object spread property copying. |
| cjs/_object_without_properties.cjs | safe | No malicious patterns detected; the file is a legitimate Babel helper for copying object properties while excluding specified keys. |
| cjs/_object_without_properties_loose.cjs | safe | No malicious patterns detected |
| cjs/_overload_yield.cjs | safe | No malicious patterns detected; the file only defines and exports a simple constructor function. |
| cjs/_possible_constructor_return.cjs | safe | No malicious patterns detected |
| cjs/_read_only_error.cjs | safe | No malicious patterns detected |
| cjs/_set.cjs | safe | No malicious patterns detected |
| cjs/_set_prototype_of.cjs | safe | No malicious patterns detected |
| cjs/_skip_first_generator_next.cjs | safe | The file contains a trivial generator-skipping utility with no network, filesystem, process, or obfuscation behavior. |
| cjs/_sliced_to_array.cjs | safe | No malicious patterns detected; the file is a standard Babel helper for array destructuring. |
| cjs/_sliced_to_array_loose.cjs | safe | No malicious patterns detected; the file is a standard Babel helper for loose array destructuring with only module imports and no network, filesystem, process, or dynamic code execution. |
| cjs/_super_prop_base.cjs | safe | No malicious patterns detected |
| cjs/_tagged_template_literal.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_tagged_template_literal_loose.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_throw.cjs | safe | No malicious patterns detected; the file only exports a trivial helper function that rethrows its argument. |
| cjs/_to_array.cjs | safe | No malicious patterns detected; this is a standard Babel helper function that converts values to arrays using only local module imports. |
| cjs/_to_consumable_array.cjs | safe | This is a standard Babel transpilation helper for converting iterables to arrays with no malicious patterns, network activity, or code execution. |
| cjs/_to_primitive.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_to_property_key.cjs | safe | No malicious patterns detected |
| cjs/_ts_add_disposable_resource.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_ts_decorate.cjs | safe | No malicious patterns detected |
| cjs/_ts_dispose_resources.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_ts_generator.cjs | safe | No malicious patterns detected |
| cjs/_ts_metadata.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_ts_param.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_ts_rewrite_relative_import_extension.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_ts_values.cjs | safe | Cleared by Jev triage; no further analysis needed |
| cjs/_type_of.cjs | safe | Code only implements a standard typeof helper with no suspicious behavior. |
| cjs/_unsupported_iterable_to_array.cjs | safe | No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays. |
| cjs/_update.cjs | safe | No malicious patterns detected |
| cjs/_using.cjs | safe | No malicious patterns detected; this is a legitimate Babel helper for 'using' declarations with resource disposal. |
| cjs/_using_ctx.cjs | safe | No malicious patterns detected; the file is a legitimate helper for implementing JavaScript using/await using declarations with proper resource disposal and error handling. |
| cjs/_wrap_async_generator.cjs | safe | No malicious patterns detected; the code is a standard Babel async generator wrapper. |
| cjs/_wrap_native_super.cjs | safe | No malicious patterns detected; this is a standard Babel helper for wrapping native superclass constructors with no network, filesystem, process, or dynamic code execution behavior. |
| cjs/_wrap_reg_exp.cjs | safe | No malicious patterns detected; the code implements a RegExp wrapper with named group extraction and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behaviors. |
| cjs/_write_only_error.cjs | safe | No malicious patterns detected; the code is a simple utility function that throws a TypeError for write-only properties. |
| cjs/index.cjs | safe | No malicious patterns detected; the file is an auto-generated CommonJS barrel file that lazily re-exports Babel runtime helpers via relative requires. |
| esm/_apply_decorated_descriptor.js | safe | This is a legitimate Babel/TypeScript-style helper for applying decorators; the concatenated property names ('keys', 'defineProperty') are a known obfuscation-avoidance technique used by transpilers, not malicious, and no exfiltration, credential harvesting, dynamic execution, or install-time code is present. |
| esm/_apply_decs_2203_r.js | safe | No malicious patterns detected; this is a legitimate Babel decorators helper with no dynamic code execution, network access, or file system manipulation. |
| esm/_apply_decs_2311.js | safe | This is a standard Babel helper for applying decorators, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution. |
| esm/_array_like_to_array.js | safe | No malicious patterns detected; the code is a simple Babel-style helper that safely copies array-like objects. |
| esm/_array_with_holes.js | safe | No malicious patterns detected |
| esm/_array_without_holes.js | safe | No malicious patterns detected |
| esm/_assert_this_initialized.js | safe | No malicious patterns detected |
| esm/_async_generator.js | safe | No malicious patterns detected; this is a standard async generator runtime helper with no network, filesystem, process, or dynamic execution behavior. |
| esm/_async_generator_delegate.js | safe | No malicious patterns detected; this is a standard Babel helper for async generator delegation. |
| esm/_async_iterator.js | safe | This is a standard Babel/rollup-generated helper for async iterator polyfilling with no malicious patterns detected. |
| esm/_async_to_generator.js | safe | No malicious patterns detected; the file is a standard Babel async-to-generator helper with no external I/O, dynamic code execution, or credential access. |
| esm/_await_async_generator.js | safe | No malicious patterns detected |
| esm/_await_value.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_call_super.js | safe | This is a standard Babel helper for implementing ES6 class inheritance, with no malicious patterns detected. |
| esm/_check_private_redeclaration.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_apply_descriptor_destructure.js | safe | No malicious patterns detected |
| esm/_class_apply_descriptor_get.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_apply_descriptor_set.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_apply_descriptor_update.js | safe | No malicious patterns detected; the code is a standard Babel/TypeScript helper for handling private class field descriptors. |
| esm/_class_call_check.js | safe | No malicious patterns detected |
| esm/_class_check_private_static_access.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_check_private_static_field_descriptor.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_extract_field_descriptor.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_name_tdz_error.js | safe | No malicious patterns detected |
| esm/_class_private_field_destructure.js | safe | No malicious patterns detected |
| esm/_class_private_field_get.js | safe | No malicious patterns detected; the file is a simple Babel/TypeScript helper for private class field access. |
| esm/_class_private_field_init.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_private_field_loose_base.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_private_field_loose_key.js | safe | No malicious patterns detected |
| esm/_class_private_field_set.js | safe | No malicious patterns detected |
| esm/_class_private_field_update.js | safe | No malicious patterns detected |
| esm/_class_private_method_get.js | safe | No malicious patterns detected; the code is a standard Babel/TypeScript helper for accessing private class methods. |
| esm/_class_private_method_init.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_class_private_method_set.js | safe | No malicious patterns detected; the file only defines a helper that throws a TypeError when private methods are reassigned, which is standard Babel transpilation output. |
| esm/_class_static_private_field_destructure.js | safe | No malicious patterns detected |
| esm/_class_static_private_field_spec_get.js | safe | No malicious patterns detected |
| esm/_class_static_private_field_spec_set.js | safe | No malicious patterns detected |
| esm/_class_static_private_field_update.js | safe | This is a standard Babel helper function for private static field updates with no malicious patterns detected. |
| esm/_class_static_private_method_get.js | safe | No malicious patterns detected; the file is a standard Babel helper for private static method access. |
| esm/_construct.js | safe | This is a standard Babel helper for ES6 Reflect.construct with no malicious patterns. |
| esm/_create_class.js | safe | No malicious patterns detected; this is a standard Babel helper for defining class properties. |
| esm/_create_for_of_iterator_helper_loose.js | safe | No malicious patterns detected |
| esm/_create_super.js | safe | No malicious patterns detected |
| esm/_decorate.js | safe | This is a standard Babel/TypeScript decorator transformation helper with no malicious patterns, network calls, process spawning, or credential access. |
| esm/_defaults.js | safe | No malicious patterns detected |
| esm/_define_enumerable_properties.js | safe | No malicious patterns detected; the code is a standard Babel helper for defining enumerable properties. |
| esm/_define_property.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_dispose.js | safe | The code implements a standard polyfill for the Explicit Resource Management 'dispose' helper (SuppressedError and resource cleanup) with no malicious patterns such as data exfiltration, environment harvesting, dynamic code execution, or network activity. |
| esm/_export_star.js | safe | No malicious patterns detected; the code is a standard ES module helper for re-exporting properties with lazy getters. |
| esm/_extends.js | safe | This is a standard Babel helper function for Object.assign polyfill with no malicious patterns. |
| esm/_get.js | safe | No malicious patterns detected; the code is a standard Babel helper for accessing superclass properties and shows no signs of exfiltration, obfuscation, or unauthorized system access. |
| esm/_get_prototype_of.js | safe | No malicious patterns detected; the code is a standard Babel helper for retrieving object prototypes. |
| esm/_identity.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_inherits.js | safe | No malicious patterns detected |
| esm/_inherits_loose.js | safe | This is a standard Babel helper function for loose prototypal inheritance with no malicious patterns. |
| esm/_initializer_define_property.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_initializer_warning_helper.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_instanceof.js | safe | No malicious patterns detected; this is a standard SWC helper implementing instanceof with Symbol.hasInstance support. |
| esm/_interop_require_default.js | safe | No malicious patterns detected; this is a standard ES module interop helper function. |
| esm/_interop_require_wildcard.js | safe | No malicious patterns detected; the code is a standard Babel/TypeScript interop helper for wildcard require with WeakMap caching. |
| esm/_is_native_function.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_is_native_reflect_construct.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_iterable_to_array.js | safe | No malicious patterns detected |
| esm/_iterable_to_array_limit.js | safe | This is a standard Babel helper function for converting a limited iterable to an array, with no malicious patterns detected. |
| esm/_iterable_to_array_limit_loose.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays with a length limit. |
| esm/_jsx.js | safe | No malicious patterns detected; this is a standard React JSX runtime helper with no network, filesystem, process, or dynamic execution behavior. |
| esm/_new_arrow_check.js | safe | No malicious patterns detected |
| esm/_non_iterable_rest.js | safe | No malicious patterns detected |
| esm/_non_iterable_spread.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_object_destructuring_empty.js | safe | No malicious patterns detected; the file only contains a small helper that throws on null/undefined destructuring. |
| esm/_object_spread.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing object spread semantics. |
| esm/_object_spread_props.js | safe | No malicious patterns detected; the code is a standard Babel-style object spread helper with no network, filesystem, process, or dynamic execution behavior. |
| esm/_object_without_properties.js | safe | This is a standard utility function that creates a shallow copy of an object excluding specified keys, with no network, filesystem, process execution, or credential-related behavior. |
| esm/_object_without_properties_loose.js | safe | This is a standard Babel helper function for creating object copies excluding specified properties, with no malicious patterns detected. |
| esm/_overload_yield.js | safe | The file defines a trivial helper class for wrapping yield values and exports it; no malicious patterns or risky behaviors are present. |
| esm/_read_only_error.js | safe | No malicious patterns detected |
| esm/_set.js | safe | No malicious patterns detected |
| esm/_set_prototype_of.js | safe | This is a standard Babel helper for setting object prototypes; no malicious patterns detected. |
| esm/_skip_first_generator_next.js | safe | No malicious patterns detected |
| esm/_sliced_to_array.js | safe | No malicious patterns detected; this is a standard Babel helper function for ES module interop. |
| esm/_sliced_to_array_loose.js | safe | No malicious patterns detected; the file is a standard Babel helper for loose array destructuring. |
| esm/_super_prop_base.js | safe | No malicious patterns detected |
| esm/_tagged_template_literal.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_tagged_template_literal_loose.js | safe | No malicious patterns detected |
| esm/_throw.js | safe | No malicious patterns detected |
| esm/_to_array.js | safe | This is a standard Babel helper function that converts iterables to arrays with no malicious patterns detected. |
| esm/_to_consumable_array.js | safe | The file is a standard Babel helper for converting iterables to arrays and contains no malicious patterns. |
| esm/_to_primitive.js | safe | No malicious patterns detected; the code is a standard JavaScript helper for converting objects to primitive values, with no network, filesystem, process, or obfuscation concerns. |
| esm/_to_property_key.js | safe | No malicious patterns detected |
| esm/_ts_add_disposable_resource.js | safe | No malicious patterns detected; this is a benign TypeScript helper re-export from tslib. |
| esm/_ts_decorate.js | safe | No malicious patterns detected |
| esm/_ts_dispose_resources.js | safe | No malicious patterns detected |
| esm/_ts_generator.js | safe | This is a standard TypeScript/JavaScript generator runtime helper with no malicious patterns detected. |
| esm/_ts_metadata.js | safe | The file simply re-exports the __metadata helper from the standard tslib package with no malicious patterns. |
| esm/_ts_param.js | safe | No malicious patterns detected |
| esm/_ts_rewrite_relative_import_extension.js | safe | No malicious patterns detected |
| esm/_ts_values.js | safe | No malicious patterns detected |
| esm/_type_of.js | safe | The file is a standard @swc/helpers typeof utility with no malicious patterns, network access, process spawning, or dynamic code execution. |
| esm/_unsupported_iterable_to_array.js | safe | No malicious patterns detected |
| esm/_update.js | safe | No malicious patterns detected; the file is a simple utility that delegates property access to _get and _set helper functions. |
| esm/_using.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_using_ctx.js | safe | This is a standard Babel helper for the JavaScript 'using' declarations (explicit resource management) proposal, containing no malicious patterns, network access, file system operations, or dynamic code execution. |
| esm/_wrap_async_generator.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_wrap_native_super.js | safe | No malicious patterns detected; the code is a standard Babel helper for wrapping native superclasses, with no external network, filesystem, process, or dynamic code execution behaviors. |
| esm/_wrap_reg_exp.js | safe | No malicious patterns detected; the code is a Babel helper for wrapping RegExp objects to support custom groups and source properties. |
| esm/_write_only_error.js | safe | No malicious patterns detected |
| esm/index.js | safe | This file is a standard Babel runtime re-export barrel with static, relative-path exports and no executable or suspicious code. |
| scripts/ast_grep.js | safe | No malicious patterns detected; the code is a legitimate AST-based build script that transforms ESM to CJS. |
| scripts/build.js | safe | The build script is a standard development utility that generates package exports and runs formatting; no malicious patterns were found. |
| scripts/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| scripts/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| src/_apply_decorated_descriptor.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_apply_decs_2203_r.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_apply_decs_2311.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_array_like_to_array.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_array_with_holes.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_array_without_holes.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_assert_this_initialized.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_async_generator.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_async_generator_delegate.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_async_iterator.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_async_to_generator.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_await_async_generator.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_await_value.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_call_super.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_check_private_redeclaration.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_apply_descriptor_destructure.mjs | safe | This file is a simple re-export statement with no executable logic or malicious patterns. |
| src/_class_apply_descriptor_get.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_apply_descriptor_set.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_apply_descriptor_update.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_call_check.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_check_private_static_access.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_check_private_static_field_descriptor.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_extract_field_descriptor.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_name_tdz_error.mjs | safe | No malicious patterns detected |
| src/_class_private_field_destructure.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_field_get.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_field_init.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_field_loose_base.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_field_loose_key.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_field_set.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_field_update.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_method_get.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_private_method_init.mjs | safe | No malicious patterns detected |
| src/_class_private_method_set.mjs | safe | No malicious patterns detected |
| src/_class_static_private_field_destructure.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_static_private_field_spec_get.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_static_private_field_spec_set.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_static_private_field_update.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_class_static_private_method_get.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_construct.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_create_class.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_create_for_of_iterator_helper_loose.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_create_super.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_decorate.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_defaults.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_define_enumerable_properties.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_define_property.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_dispose.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_export_star.mjs | safe | No malicious patterns detected |
| src/_extends.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_get.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_get_prototype_of.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_identity.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_inherits.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_inherits_loose.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_initializer_define_property.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_initializer_warning_helper.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_instanceof.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_interop_require_default.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_interop_require_wildcard.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_is_native_function.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_is_native_reflect_construct.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_iterable_to_array.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_iterable_to_array_limit.mjs | safe | No malicious patterns detected |
| src/_iterable_to_array_limit_loose.mjs | safe | This file is a simple re-export that forwards the default export from another module without any malicious patterns or suspicious behavior. |
| src/_jsx.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_new_arrow_check.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_non_iterable_rest.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_non_iterable_spread.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_object_destructuring_empty.mjs | safe | This file is a simple re-export shim with no executable logic or malicious patterns. |
| src/_object_spread.mjs | safe | No malicious patterns detected |
| src/_object_spread_props.mjs | safe | No malicious patterns detected |
| src/_object_without_properties.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_object_without_properties_loose.mjs | safe | No malicious patterns detected; the file is a simple re-export with no executable code or suspicious behavior. |
| src/_overload_yield.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_possible_constructor_return.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_read_only_error.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_set.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_set_prototype_of.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_skip_first_generator_next.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_sliced_to_array.mjs | safe | No malicious patterns detected |
| src/_sliced_to_array_loose.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_super_prop_base.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_tagged_template_literal.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_tagged_template_literal_loose.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_throw.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_to_array.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_to_consumable_array.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_to_primitive.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_to_property_key.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_ts_add_disposable_resource.mjs | safe | The file only re-exports a default binding from another module with no executable top-level code or malicious patterns. |
| src/_ts_decorate.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_ts_dispose_resources.mjs | safe | The file is a simple re-export statement with no malicious patterns detected. |
| src/_ts_generator.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_ts_metadata.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_ts_param.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_ts_rewrite_relative_import_extension.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_ts_values.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_type_of.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_unsupported_iterable_to_array.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_update.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_using.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_using_ctx.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_wrap_async_generator.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_wrap_native_super.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_wrap_reg_exp.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/_write_only_error.mjs | safe | Cleared by Jev triage; no further analysis needed |
| src/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of @swc/helpers are flagged high or critical. The latest scanned version, 0.5.23, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 0.5.23 | Needs review | 1 | 0.5.23 | |
| 0.5.18 | Not scanned | 1 | 0.5.18 | |
| 0.5.17 | Needs review | 1 | 0.5.17 | |
| 0.5.5 | Not scanned | 1 | 0.5.5 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @swc/helpers
Frequently asked questions
Is @swc/helpers safe to use?
No confirmed malware was found in @swc/helpers@0.5.23, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does @swc/helpers contain malware?
No malware was identified in @swc/helpers@0.5.23 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @swc/helpers checked?
Togoder Security downloaded the published npm package and had an AI model read its 328 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @swc/helpers together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @swc/helpers@0.5.23, cost nothing.