Togoder security

npm package security report

any-promise npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.3.0 Files reviewed 16 Size 6.9 KB Scanned

Summary

Togoder Security scanned the npm package any-promise@1.3.0 on Oct 6, 2026. An AI review of 16 source files produced 6 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
6
medium
5
low

Findings 11

medium

dynamic module loading / deferred execution

NPS-4A8DAAFD000C

The file immediately requires './register' and invokes it as a function at import time, then accesses the 'implementation' property. This means arbitrary code inside './register' runs automatically upon import. Without inspecting './register', the actual behavior cannot be verified, but this pattern is a common mechanism used to hide malicious install-time or import-time behavior in a separate module. It obscures the real entry point and could execute network requests, credential harvesting, file system access, or shell commands at require time.

implementation.js:1
medium

dynamic module loading

NPS-A0AAB1DCAEE2

The file delegates to './register' at import time, meaning the actual behavior is entirely determined by an unanalyzed sibling file. This pattern is commonly used to hide malicious logic in a separate module while keeping index.js innocuous. The returned object's .Promise property also suggests runtime monkey-patching of the global Promise, which can enable interception of async operations.

index.js:1
medium

Dynamic module loading with external input

NPS-B986F23445BD

The loadImplementation function uses require(implementation) where 'implementation' is a parameter that can be controlled by the caller. If an attacker can influence this parameter, they could load arbitrary modules, potentially leading to code execution or loading malicious packages. The auto-detection also iterates over a hardcoded list of common promise libraries and attempts to require each one, which is less concerning as the list is fixed.

register.js:22
medium

Dynamic Module Loading with Computed Dependency

NPS-087812328FFD

The require('../register') call is a relative module load whose behavior depends entirely on the content of ../register.js, which is not provided for analysis. If that file has been tampered with, this entry point could trigger arbitrary code execution on import.

register/es6-promise.js:2
medium

Dynamic require with external package reference

NPS-9DA1B52F047F

The file requires '../register' and immediately invokes it with the module name 'vow' and a Promise reference from the 'vow' package. This is a dynamic module-loading pattern that depends on a sibling module ('../register') not shown here. While the intent appears to be polyfilling Promise with vow's Promise, the actual behavior depends entirely on the unprovided '../register' implementation, which could perform arbitrary actions at import time.

register/vow.js:2
medium

Top-level code execution on import

NPS-DBC6DFAC1701

The require call executes at module load time, meaning any side effects in '../register' will run whenever this file is imported. This is a common vector for supply-chain attacks where a seemingly benign wrapper triggers hidden behavior in a separate module.

register/vow.js:2
low

Dynamic module loading with fallback

NPS-BC2845B96AE9

The file dynamically requires './register' and executes the returned function at import time. While the import path is static and not user-controlled, it does execute code from a sibling module during import, which is a common pattern in utility polyfills but could be leveraged for conditional loading behavior. No obfuscation or external input is used.

optional.js:3
low

Silent error handling

NPS-6BA155DEB55C

The catch block silently swallows all exceptions and exports null. This can mask failures or malicious behavior in the 'register' module, making analysis harder, though it is not inherently malicious.

optional.js:5
low

Top-level execution on import

NPS-7AFED71E823A

The module executes code immediately upon import: module.exports = require('./loader')(global, loadImplementation). This invokes the loader function, which may perform side effects such as auto-detecting and loading promise implementations, potentially requiring various packages. While this is typical for polyfill libraries, it represents import-time execution that could have unintended consequences if the environment is compromised or if the auto-detection loads an unexpected module.

register.js:2
low

Install/Import Time Code Execution

NPS-F63B295A82A6

This file executes at import time. It calls require('../register') with a package name and a Promise implementation, which is a known pattern used by libraries like core-js to register/override the global Promise at load time. While this specific usage appears to be a legitimate polyfill registration mechanism, the pattern of modifying global objects during import is a common technique for supply-chain attacks and should be reviewed in the broader context of the '../register' module.

register/es6-promise.js:2
low

dynamic module loading / require at import time

NPS-5A77220D2E2D

The file calls require('../register') at the top level, which dynamically loads a sibling module and passes a promise implementation object. This is a common pattern in promise polyfill/registration packages, but it executes immediately upon import and relies on a relative path outside the analyzed file. If the parent register module or the 'when' package were compromised, this could serve as an indirect loader. However, no data exfiltration, credential access, obfuscation, shell commands, or network activity is present in this file itself.

register/when.js:2

Files reviewed

FileVerdictWhat the reviewer saw
implementation.js medium This one-line redirector invokes code from './register' at import time, hiding the actual implementation and requiring further inspection of that referenced module to confirm safety.
index.js medium index.js is a thin wrapper that defers all behavior to an unanalyzed './register' module at import time, requiring inspection of that file to determine intent.
optional.js medium The file contains no direct malicious indicators, but dynamically executes a sibling module at import time and silently suppresses errors, which warrants caution and further review of the referenced './register' module.
register.js medium The code dynamically requires modules based on input parameters and executes logic at import time, which could pose a medium risk if the implementation parameter is attacker-controlled, but no direct malicious patterns were found.
register/es6-promise.js medium This file is a thin shim that registers es6-promise at import time; no direct malicious patterns are present, but it relies on an unanalyzed '../register' module and modifies global state, warranting further review of the referenced file.
register/vow.js medium The file is a thin wrapper that dynamically loads a local '../register' module at import time; without inspecting that module, its true behavior and any side effects cannot be verified, warranting caution.
register/when.js medium The file is a small top-level module that delegates to a relative register module and the 'when' package; no malicious patterns are evident, but import-time dynamic loading warrants low-severity caution.
loader.js safe No malicious patterns detected; the code is a legitimate any-promise registration loader with no network, filesystem, or execution risks.
register-shim.js safe No malicious patterns detected
register/bluebird.js safe No malicious patterns detected
register/lie.js safe This file is a simple Promise implementation registration that requires the local register module and the 'lie' package, with no malicious patterns detected.
register/native-promise-only.js safe The file simply registers a promise polyfill module; no malicious patterns detected
register/pinkie.js safe No malicious patterns detected
register/promise.js safe No malicious patterns detected; the file is a simple registration shim for the 'promise' package.
register/q.js safe No malicious patterns detected
register/rsvp.js safe No malicious patterns detected; the file simply registers the 'rsvp' Promise implementation with the core-js polyfill loader.

Scanned versions of any-promise

VersionVerdictFilesScanned
1.3.0 Needs review 16 Oct 6, 2026

Frequently asked questions

Is any-promise safe to use?

No confirmed malware was found in any-promise@1.3.0, but the review flagged 6 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does any-promise contain malware?

No malware was identified in any-promise@1.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was any-promise checked?

Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan any-promise together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in any-promise@1.3.0, cost nothing.

Related security reports