Summary
Togoder Security scanned the npm package @vitest/mocker@5.0.3 on Oct 6, 2026. An AI review of 16 source files produced 1 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
Dynamic code execution (eval)
NPS-C97DAF2D64AC
The embedded es-module-lexer code includes a function i(A) that performs (0,eval)(A) to decode JavaScript string literals (e.g., import specifiers). While this is obfuscated/minified third-party WASM loader code from es-module-lexer and is used only for parsing string literals, the presence of eval on filesystem-sourced string data warrants attention.
Global object manipulation
NPS-9BE4F51B52B3
The class sets a global accessor string ('__vitest_mocker__') by default, which is used to provide module mocking functionality. This is typical for testing frameworks but could interfere with global state if misused.
Dynamic import with external module loading
NPS-E1F64EAF29D9
The code dynamically imports 'msw/browser' and 'msw/core/http' at runtime. While these are legitimate Mock Service Worker dependencies, dynamic imports can introduce supply chain risks if the dependency is compromised or if the import path is manipulated. However, the import paths are hardcoded, limiting the risk.
Response redirection with user-controlled input
NPS-BA84A8980F82
The code uses Response.redirect with values derived from mock configurations (mock.redirect, and injectQuery with mock.type). While not directly exploitable in this snippet, if mock configurations are attacker-controlled, this could lead to open redirects or other manipulation.
Embedded WebAssembly binary payload
NPS-FC48F81A2A8A
The file contains two large base64-encoded WebAssembly binaries (cjs-module-lexer 2.2.1 and es-module-lexer 2.3.2) that are compiled and instantiated at runtime via WebAssembly.compile/instantiate. This is standard for these well-known npm packages but the binary blob itself is opaque and cannot be audited in source form.
File system reads and dynamic module resolution
NPS-C98A9AE570BA
collectModuleExports reads arbitrary files from disk (readFileSync) and resolves/parses external modules based on import/require specifiers found in the analyzed code, including using createRequire and import.meta.resolve. This is core intended functionality for Vitest module mocking, not exfiltration, but expands the attack surface when automocking untrusted modules.
Dynamic code generation via MagicString output
NPS-8660F63536EF
automockModule programmatically generates JavaScript source strings (moduleObject, assigning, specifiersExports) using values derived from parsed source code (export names, specifiers). Export names are interpolated into generated code strings — an attacker-controlled export identifier containing quotes/backticks could theoretically inject code into the generated module, though typical AST parsing constrains identifiers.
Environment variable inspection
NPS-9DF688E76157
Reads process.env.NODE_OPTIONS and process.execArgv to detect --experimental-transform-types. This is benign configuration detection, not credential harvesting.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/browser.js | medium | The code appears to be a legitimate testing utility for module mocking with Mock Service Worker, but uses dynamic imports and response redirection that warrant low-severity caution. |
| dist/chunk-automock.js | medium | This is a legitimate Vitest internal chunk for module automocking that includes bundled es-module-lexer/cjs-module-lexer WASM payloads and uses eval for string literal decoding; no exfiltration, credential harvesting, shell execution, or backdoor patterns were found. |
| dist/auto-register.js | safe | No malicious patterns detected; the file only wires up Vitest's module mocker and imports internal chunks. |
| dist/automock.js | safe | The file only contains static ES module imports and a re-export, with no suspicious, dynamic, or malicious behavior. |
| dist/chunk-helpers.js | safe | No malicious patterns detected |
| dist/chunk-hoistMocks.js | safe | This file is a legitimate Vitest internals module that hoists vi.mock/vi.hoisted calls and transforms imports; it performs no exfiltration, credential access, code execution, or other malicious behavior. |
| dist/chunk-interceptor-native.js | safe | This is a Vitest internal module mocker interceptor that only uses an RPC channel to register/delete/invalidate module mocks; no malicious patterns detected. |
| dist/chunk-mocker.js | safe | No malicious patterns detected; the code is part of Vitest's module mocking infrastructure and only performs local testing-related operations. |
| dist/chunk-pathe.M-eThtNZ.js | safe | No malicious patterns detected in this pure path normalization utility module. |
| dist/chunk-registry.js | safe | No malicious patterns detected |
| dist/chunk-utils.js | safe | The code only cleans URLs and dynamically generates ES module source strings for Vitest's module mocking system; it contains no network, filesystem, credential, process, or obfuscation-based malicious patterns. |
| dist/index.js | safe | This is a legitimate Vitest mocking utility with no malicious patterns, network activity, credential harvesting, or code execution concerns. |
| dist/node.js | safe | No malicious patterns detected |
| dist/redirect.js | safe | No malicious patterns detected |
| dist/register.js | safe | No malicious patterns detected; the code is a legitimate Vitest module mocker registration that uses RPC for internal communication and does not perform any exfiltration, credential harvesting, or dynamic code execution. |
| dist/transforms.js | safe | No malicious patterns detected; the file only re-exports functions from local chunks and imports standard Node.js/third-party utility modules. |
Frequently asked questions
Is @vitest/mocker safe to use?
No confirmed malware was found in @vitest/mocker@5.0.3, but the review flagged 1 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does @vitest/mocker contain malware?
No malware was identified in @vitest/mocker@5.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @vitest/mocker checked?
Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @vitest/mocker together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @vitest/mocker@5.0.3, cost nothing.