Togoder security

npm package security report

@vitest/mocker npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 5.0.3 Files reviewed 16 Size 152.5 KB Scanned

Summary

Togoder Security scanned the npm package @vitest/mocker@5.0.3 on Oct 6, 2026. An AI review of 16 source files produced 1 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
7
low

Findings 8

medium

Dynamic code execution (eval)

NPS-C97DAF2D64AC

The embedded es-module-lexer code includes a function i(A) that performs (0,eval)(A) to decode JavaScript string literals (e.g., import specifiers). While this is obfuscated/minified third-party WASM loader code from es-module-lexer and is used only for parsing string literals, the presence of eval on filesystem-sourced string data warrants attention.

dist/chunk-automock.js
low

Global object manipulation

NPS-9BE4F51B52B3

The class sets a global accessor string ('__vitest_mocker__') by default, which is used to provide module mocking functionality. This is typical for testing frameworks but could interfere with global state if misused.

dist/browser.js:21
low

Dynamic import with external module loading

NPS-E1F64EAF29D9

The code dynamically imports 'msw/browser' and 'msw/core/http' at runtime. While these are legitimate Mock Service Worker dependencies, dynamic imports can introduce supply chain risks if the dependency is compromised or if the import path is manipulated. However, the import paths are hardcoded, limiting the risk.

dist/browser.js:68
low

Response redirection with user-controlled input

NPS-BA84A8980F82

The code uses Response.redirect with values derived from mock configurations (mock.redirect, and injectQuery with mock.type). While not directly exploitable in this snippet, if mock configurations are attacker-controlled, this could lead to open redirects or other manipulation.

dist/browser.js:87
low

Embedded WebAssembly binary payload

NPS-FC48F81A2A8A

The file contains two large base64-encoded WebAssembly binaries (cjs-module-lexer 2.2.1 and es-module-lexer 2.3.2) that are compiled and instantiated at runtime via WebAssembly.compile/instantiate. This is standard for these well-known npm packages but the binary blob itself is opaque and cannot be audited in source form.

dist/chunk-automock.js
low

File system reads and dynamic module resolution

NPS-C98A9AE570BA

collectModuleExports reads arbitrary files from disk (readFileSync) and resolves/parses external modules based on import/require specifiers found in the analyzed code, including using createRequire and import.meta.resolve. This is core intended functionality for Vitest module mocking, not exfiltration, but expands the attack surface when automocking untrusted modules.

dist/chunk-automock.js
low

Dynamic code generation via MagicString output

NPS-8660F63536EF

automockModule programmatically generates JavaScript source strings (moduleObject, assigning, specifiersExports) using values derived from parsed source code (export names, specifiers). Export names are interpolated into generated code strings — an attacker-controlled export identifier containing quotes/backticks could theoretically inject code into the generated module, though typical AST parsing constrains identifiers.

dist/chunk-automock.js
low

Environment variable inspection

NPS-9DF688E76157

Reads process.env.NODE_OPTIONS and process.execArgv to detect --experimental-transform-types. This is benign configuration detection, not credential harvesting.

dist/chunk-automock.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/browser.js medium The code appears to be a legitimate testing utility for module mocking with Mock Service Worker, but uses dynamic imports and response redirection that warrant low-severity caution.
dist/chunk-automock.js medium This is a legitimate Vitest internal chunk for module automocking that includes bundled es-module-lexer/cjs-module-lexer WASM payloads and uses eval for string literal decoding; no exfiltration, credential harvesting, shell execution, or backdoor patterns were found.
dist/auto-register.js safe No malicious patterns detected; the file only wires up Vitest's module mocker and imports internal chunks.
dist/automock.js safe The file only contains static ES module imports and a re-export, with no suspicious, dynamic, or malicious behavior.
dist/chunk-helpers.js safe No malicious patterns detected
dist/chunk-hoistMocks.js safe This file is a legitimate Vitest internals module that hoists vi.mock/vi.hoisted calls and transforms imports; it performs no exfiltration, credential access, code execution, or other malicious behavior.
dist/chunk-interceptor-native.js safe This is a Vitest internal module mocker interceptor that only uses an RPC channel to register/delete/invalidate module mocks; no malicious patterns detected.
dist/chunk-mocker.js safe No malicious patterns detected; the code is part of Vitest's module mocking infrastructure and only performs local testing-related operations.
dist/chunk-pathe.M-eThtNZ.js safe No malicious patterns detected in this pure path normalization utility module.
dist/chunk-registry.js safe No malicious patterns detected
dist/chunk-utils.js safe The code only cleans URLs and dynamically generates ES module source strings for Vitest's module mocking system; it contains no network, filesystem, credential, process, or obfuscation-based malicious patterns.
dist/index.js safe This is a legitimate Vitest mocking utility with no malicious patterns, network activity, credential harvesting, or code execution concerns.
dist/node.js safe No malicious patterns detected
dist/redirect.js safe No malicious patterns detected
dist/register.js safe No malicious patterns detected; the code is a legitimate Vitest module mocker registration that uses RPC for internal communication and does not perform any exfiltration, credential harvesting, or dynamic code execution.
dist/transforms.js safe No malicious patterns detected; the file only re-exports functions from local chunks and imports standard Node.js/third-party utility modules.

Scanned versions of @vitest/mocker

VersionVerdictFilesScanned
5.0.3 Needs review 16 Oct 6, 2026

Frequently asked questions

Is @vitest/mocker safe to use?

No confirmed malware was found in @vitest/mocker@5.0.3, but the review flagged 1 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does @vitest/mocker contain malware?

No malware was identified in @vitest/mocker@5.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @vitest/mocker checked?

Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @vitest/mocker together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @vitest/mocker@5.0.3, cost nothing.

Related security reports