Togoder security

npm package security report

@typescript-eslint/typescript-estree npm package: is it safe?

No malicious code found.

No issues Version 8.70.0 Files reviewed 43 Size 308.6 KB Scanned

Summary

Togoder Security scanned the npm package @typescript-eslint/typescript-estree@8.70.0 on Oct 6, 2026. An AI review of 43 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
dist/ast-converter.js safe Cleared by Jev triage; no further analysis needed
dist/check-modifiers.js safe No malicious patterns detected; the code is a standard TypeScript ESLint helper for validating decorators and modifiers, with no network, filesystem, process, or dynamic code execution activity.
dist/check-syntax-errors.js safe No malicious patterns detected; the code is a legitimate TypeScript syntax checker that performs static AST validation without network, filesystem, process, or dynamic code execution.
dist/clear-caches.js safe No malicious patterns detected
dist/convert-comments.js safe This is a standard TypeScript utility file for converting AST comments to ESTree format with no malicious patterns detected.
dist/create-program/WatchCompilerHostOfConfigFile.js safe No malicious patterns detected
dist/create-program/createIsolatedProgram.js safe No malicious patterns detected; the file is a standard TypeScript/ESLint helper that creates an isolated in-memory TypeScript program and performs no network, filesystem, process, or credential access.
dist/create-program/createProjectProgram.js safe No malicious patterns detected; the code is a benign utility for creating TypeScript programs from project settings.
dist/create-program/createProjectProgramError.js safe No malicious patterns detected; the code only generates descriptive error messages for TypeScript ESLint configuration issues.
dist/create-program/createSourceFile.js safe No malicious patterns detected; the file contains standard TypeScript compiler import shims and a function to create source files for AST parsing.
dist/create-program/describeFilePath.js safe No malicious patterns detected; the code only computes and formats file paths relative to a tsconfig root directory using node:path.
dist/create-program/getScriptKind.js safe No malicious patterns detected; the file is a standard TypeScript helper for determining script kinds and language variants.
dist/create-program/getWatchProgramsForProjects.js safe This is a legitimate TypeScript-ESLint internal module for managing TypeScript watch programs with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
dist/create-program/shared.js safe No malicious patterns detected; the file contains standard TypeScript helper functions for compiler option and path handling.
dist/create-program/useProvidedPrograms.js safe No malicious patterns detected; the file contains standard TypeScript/ESLint helper utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity.
dist/create-program/validateDefaultProjectForFilesGlob.js safe No malicious patterns detected; the code only performs input validation on glob patterns and throws errors for overly wide patterns.
dist/createParserServices.js safe No malicious patterns detected; the file contains standard TypeScript parser service factory logic with no network, filesystem, process, or dynamic code execution behavior.
dist/getImportClausePhaseModifier.js safe No malicious patterns detected; the file contains standard TypeScript compiler API helper code for handling import clause phase modifiers.
dist/getModifiers.js safe This is a legitimate TypeScript helper file for retrieving AST node modifiers/decorators with no malicious patterns detected.
dist/index.js safe No malicious patterns detected; the code is a standard TypeScript/JavaScript module entry point re-exporting internal modules without any suspicious behavior.
dist/jsx/xhtml-entities.js safe No malicious patterns detected; the file only exports a static mapping of XHTML entity names to Unicode characters.
dist/node-utils.js safe No malicious patterns detected; the file contains standard TypeScript/ESLint utility functions with no network, filesystem, process execution, or obfuscated code.
dist/parseSettings/ExpiringCache.js safe Cleared by Jev triage; no further analysis needed
dist/parseSettings/candidateTSConfigRootDirs.js safe No malicious patterns detected; the code is a straightforward utility for managing TypeScript config root directories with no network, filesystem, process, or dynamic execution activity.
dist/parseSettings/createParseSettings.js safe This is a legitimate TypeScript-ESLint parser settings module with no malicious patterns detected.
Show 18 more files
FileVerdictWhat the reviewer saw
dist/parseSettings/getProjectConfigFiles.js safe No malicious patterns detected; the file is a standard TypeScript-ESLint utility for locating tsconfig.json files.
dist/parseSettings/index.js safe The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns.
dist/parseSettings/inferSingleRun.js safe No malicious patterns detected; the code performs benign environment-based detection of ESLint run mode without any data exfiltration, credential harvesting, or dynamic code execution.
dist/parseSettings/resolveProjectList.js safe The file is a legitimate TypeScript-ESLint utility for resolving project paths with caching; no malicious patterns were detected.
dist/parseSettings/warnAboutTSVersion.js safe No malicious patterns detected; the code is a standard TypeScript version compatibility warning utility with no network, filesystem, process, or obfuscation concerns.
dist/parser-options.js safe The file is a minimal compiled TypeScript output that only sets the __esModule marker and references a source map, with no executable, network, filesystem, or obfuscated code.
dist/parser.js safe No malicious patterns detected; the code is a standard TypeScript parser module with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
dist/semantic-or-syntactic-errors.js safe No malicious patterns detected; the file only filters TypeScript diagnostics and converts them to error objects.
dist/simple-traverse.js safe No malicious patterns detected; the code is a standard AST traversal utility with no external network, filesystem, process execution, or dynamic code loading.
dist/source-files.js safe No malicious patterns detected; the file contains standard TypeScript helper functions and utility exports.
dist/ts-estree/estree-to-ts-node-types.js safe No malicious patterns detected
dist/ts-estree/index.js safe The code is a standard TypeScript/CommonJS interoperability module with no malicious patterns, network activity, or dynamic execution.
dist/ts-estree/ts-nodes.js safe No malicious patterns detected; the file contains only standard TypeScript module boilerplate and a source map reference.
dist/use-at-your-own-risk.js safe No malicious patterns detected; the file only contains standard TypeScript compilation helpers and re-exports from internal modules.
dist/useProgramFromProjectService.js safe No malicious patterns detected; the file contains standard TypeScript/ESLint project service logic with no data exfiltration, credential harvesting, obfuscation, or process spawning.
dist/version-check.js safe No malicious patterns detected; the file is a standard TypeScript/JavaScript version-check utility using semver and typescript imports.
dist/version.js safe No malicious patterns detected; the file simply reads the package version from package.json.
dist/withoutProjectParserOptions.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of @typescript-eslint/typescript-estree

VersionVerdictFilesScanned
8.70.0 No issues 43 Oct 6, 2026

Frequently asked questions

Is @typescript-eslint/typescript-estree safe to use?

Our AI source review of @typescript-eslint/typescript-estree@8.70.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @typescript-eslint/typescript-estree contain malware?

No malware was identified in @typescript-eslint/typescript-estree@8.70.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @typescript-eslint/typescript-estree checked?

Togoder Security downloaded the published npm package and had an AI model read its 43 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @typescript-eslint/typescript-estree together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @typescript-eslint/typescript-estree@8.70.0, cost nothing.

Related security reports