Summary
Togoder Security scanned the npm package @typescript-eslint/typescript-estree@8.70.0 on Oct 6, 2026. An AI review of 43 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/ast-converter.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/check-modifiers.js | safe | No malicious patterns detected; the code is a standard TypeScript ESLint helper for validating decorators and modifiers, with no network, filesystem, process, or dynamic code execution activity. |
| dist/check-syntax-errors.js | safe | No malicious patterns detected; the code is a legitimate TypeScript syntax checker that performs static AST validation without network, filesystem, process, or dynamic code execution. |
| dist/clear-caches.js | safe | No malicious patterns detected |
| dist/convert-comments.js | safe | This is a standard TypeScript utility file for converting AST comments to ESTree format with no malicious patterns detected. |
| dist/create-program/WatchCompilerHostOfConfigFile.js | safe | No malicious patterns detected |
| dist/create-program/createIsolatedProgram.js | safe | No malicious patterns detected; the file is a standard TypeScript/ESLint helper that creates an isolated in-memory TypeScript program and performs no network, filesystem, process, or credential access. |
| dist/create-program/createProjectProgram.js | safe | No malicious patterns detected; the code is a benign utility for creating TypeScript programs from project settings. |
| dist/create-program/createProjectProgramError.js | safe | No malicious patterns detected; the code only generates descriptive error messages for TypeScript ESLint configuration issues. |
| dist/create-program/createSourceFile.js | safe | No malicious patterns detected; the file contains standard TypeScript compiler import shims and a function to create source files for AST parsing. |
| dist/create-program/describeFilePath.js | safe | No malicious patterns detected; the code only computes and formats file paths relative to a tsconfig root directory using node:path. |
| dist/create-program/getScriptKind.js | safe | No malicious patterns detected; the file is a standard TypeScript helper for determining script kinds and language variants. |
| dist/create-program/getWatchProgramsForProjects.js | safe | This is a legitimate TypeScript-ESLint internal module for managing TypeScript watch programs with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/create-program/shared.js | safe | No malicious patterns detected; the file contains standard TypeScript helper functions for compiler option and path handling. |
| dist/create-program/useProvidedPrograms.js | safe | No malicious patterns detected; the file contains standard TypeScript/ESLint helper utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity. |
| dist/create-program/validateDefaultProjectForFilesGlob.js | safe | No malicious patterns detected; the code only performs input validation on glob patterns and throws errors for overly wide patterns. |
| dist/createParserServices.js | safe | No malicious patterns detected; the file contains standard TypeScript parser service factory logic with no network, filesystem, process, or dynamic code execution behavior. |
| dist/getImportClausePhaseModifier.js | safe | No malicious patterns detected; the file contains standard TypeScript compiler API helper code for handling import clause phase modifiers. |
| dist/getModifiers.js | safe | This is a legitimate TypeScript helper file for retrieving AST node modifiers/decorators with no malicious patterns detected. |
| dist/index.js | safe | No malicious patterns detected; the code is a standard TypeScript/JavaScript module entry point re-exporting internal modules without any suspicious behavior. |
| dist/jsx/xhtml-entities.js | safe | No malicious patterns detected; the file only exports a static mapping of XHTML entity names to Unicode characters. |
| dist/node-utils.js | safe | No malicious patterns detected; the file contains standard TypeScript/ESLint utility functions with no network, filesystem, process execution, or obfuscated code. |
| dist/parseSettings/ExpiringCache.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/parseSettings/candidateTSConfigRootDirs.js | safe | No malicious patterns detected; the code is a straightforward utility for managing TypeScript config root directories with no network, filesystem, process, or dynamic execution activity. |
| dist/parseSettings/createParseSettings.js | safe | This is a legitimate TypeScript-ESLint parser settings module with no malicious patterns detected. |
Show 18 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/parseSettings/getProjectConfigFiles.js | safe | No malicious patterns detected; the file is a standard TypeScript-ESLint utility for locating tsconfig.json files. |
| dist/parseSettings/index.js | safe | The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns. |
| dist/parseSettings/inferSingleRun.js | safe | No malicious patterns detected; the code performs benign environment-based detection of ESLint run mode without any data exfiltration, credential harvesting, or dynamic code execution. |
| dist/parseSettings/resolveProjectList.js | safe | The file is a legitimate TypeScript-ESLint utility for resolving project paths with caching; no malicious patterns were detected. |
| dist/parseSettings/warnAboutTSVersion.js | safe | No malicious patterns detected; the code is a standard TypeScript version compatibility warning utility with no network, filesystem, process, or obfuscation concerns. |
| dist/parser-options.js | safe | The file is a minimal compiled TypeScript output that only sets the __esModule marker and references a source map, with no executable, network, filesystem, or obfuscated code. |
| dist/parser.js | safe | No malicious patterns detected; the code is a standard TypeScript parser module with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior. |
| dist/semantic-or-syntactic-errors.js | safe | No malicious patterns detected; the file only filters TypeScript diagnostics and converts them to error objects. |
| dist/simple-traverse.js | safe | No malicious patterns detected; the code is a standard AST traversal utility with no external network, filesystem, process execution, or dynamic code loading. |
| dist/source-files.js | safe | No malicious patterns detected; the file contains standard TypeScript helper functions and utility exports. |
| dist/ts-estree/estree-to-ts-node-types.js | safe | No malicious patterns detected |
| dist/ts-estree/index.js | safe | The code is a standard TypeScript/CommonJS interoperability module with no malicious patterns, network activity, or dynamic execution. |
| dist/ts-estree/ts-nodes.js | safe | No malicious patterns detected; the file contains only standard TypeScript module boilerplate and a source map reference. |
| dist/use-at-your-own-risk.js | safe | No malicious patterns detected; the file only contains standard TypeScript compilation helpers and re-exports from internal modules. |
| dist/useProgramFromProjectService.js | safe | No malicious patterns detected; the file contains standard TypeScript/ESLint project service logic with no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/version-check.js | safe | No malicious patterns detected; the file is a standard TypeScript/JavaScript version-check utility using semver and typescript imports. |
| dist/version.js | safe | No malicious patterns detected; the file simply reads the package version from package.json. |
| dist/withoutProjectParserOptions.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is @typescript-eslint/typescript-estree safe to use?
Our AI source review of @typescript-eslint/typescript-estree@8.70.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @typescript-eslint/typescript-estree contain malware?
No malware was identified in @typescript-eslint/typescript-estree@8.70.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @typescript-eslint/typescript-estree checked?
Togoder Security downloaded the published npm package and had an AI model read its 43 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @typescript-eslint/typescript-estree together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @typescript-eslint/typescript-estree@8.70.0, cost nothing.