Summary
Togoder Security scanned the npm package abort-controller@3.0.0 on Oct 4, 2026. An AI review of 7 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Dynamic code execution
NPS-813BCCAA7A6D
The code uses Function("return this")() to obtain the global object when module and define are undefined. While this pattern is a known UMD fallback and not inherently malicious, new Function (or Function constructor) is a dynamic code execution primitive that could be abused if input were ever passed to it. Here the string is static, so risk is low, but it is a red flag worth noting.
Global object modification
NPS-C9AB215790FC
At the end of the UMD wrapper, the code checks for AbortController on the global object and conditionally assigns AbortController and AbortSignal polyfills. This modifies global state, which is expected for a polyfill but should be noted as it affects the runtime environment.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/abort-controller.umd.js | medium | The file is a standard UMD polyfill for AbortController/AbortSignal with no malicious network, filesystem, credential-harvesting, or process-spawning behavior; only minor concerns are the use of the Function constructor and global mutation typical of polyfills. |
| browser.js | safe | Cleared by Jev triage; no further analysis needed |
| browser.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/abort-controller.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/abort-controller.mjs | safe | Cleared by Jev triage; no further analysis needed |
| polyfill.js | safe | No malicious patterns detected; the code is a standard polyfill for AbortController and AbortSignal that conditionally assigns them to the global object. |
| polyfill.mjs | safe | No malicious patterns detected |
Scanned versions of abort-controller
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 3.0.0 | Needs review | 7 | Oct 4, 2026 |
Frequently asked questions
Is abort-controller safe to use?
No confirmed malware was found in abort-controller@3.0.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does abort-controller contain malware?
No malware was identified in abort-controller@3.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was abort-controller checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan abort-controller together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in abort-controller@3.0.0, cost nothing.