# any-promise@1.3.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:13:44.000Z
- Files reviewed: 16
- Findings: 6 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/any-promise
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package any-promise@1.3.0 on Oct 6, 2026. An AI review of 16 source files produced 6 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic module loading / deferred execution

Finding ID: `NPS-4A8DAAFD000C`

File: `implementation.js:1`

The file immediately requires './register' and invokes it as a function at import time, then accesses the 'implementation' property. This means arbitrary code inside './register' runs automatically upon import. Without inspecting './register', the actual behavior cannot be verified, but this pattern is a common mechanism used to hide malicious install-time or import-time behavior in a separate module. It obscures the real entry point and could execute network requests, credential harvesting, file system access, or shell commands at require time.

### [medium] dynamic module loading

Finding ID: `NPS-A0AAB1DCAEE2`

File: `index.js:1`

The file delegates to './register' at import time, meaning the actual behavior is entirely determined by an unanalyzed sibling file. This pattern is commonly used to hide malicious logic in a separate module while keeping index.js innocuous. The returned object's .Promise property also suggests runtime monkey-patching of the global Promise, which can enable interception of async operations.

### [medium] Dynamic module loading with external input

Finding ID: `NPS-B986F23445BD`

File: `register.js:22`

The loadImplementation function uses require(implementation) where 'implementation' is a parameter that can be controlled by the caller. If an attacker can influence this parameter, they could load arbitrary modules, potentially leading to code execution or loading malicious packages. The auto-detection also iterates over a hardcoded list of common promise libraries and attempts to require each one, which is less concerning as the list is fixed.

### [medium] Dynamic Module Loading with Computed Dependency

Finding ID: `NPS-087812328FFD`

File: `register/es6-promise.js:2`

The require('../register') call is a relative module load whose behavior depends entirely on the content of ../register.js, which is not provided for analysis. If that file has been tampered with, this entry point could trigger arbitrary code execution on import.

### [medium] Dynamic require with external package reference

Finding ID: `NPS-9DA1B52F047F`

File: `register/vow.js:2`

The file requires '../register' and immediately invokes it with the module name 'vow' and a Promise reference from the 'vow' package. This is a dynamic module-loading pattern that depends on a sibling module ('../register') not shown here. While the intent appears to be polyfilling Promise with vow's Promise, the actual behavior depends entirely on the unprovided '../register' implementation, which could perform arbitrary actions at import time.

### [medium] Top-level code execution on import

Finding ID: `NPS-DBC6DFAC1701`

File: `register/vow.js:2`

The require call executes at module load time, meaning any side effects in '../register' will run whenever this file is imported. This is a common vector for supply-chain attacks where a seemingly benign wrapper triggers hidden behavior in a separate module.

### [low] Dynamic module loading with fallback

Finding ID: `NPS-BC2845B96AE9`

File: `optional.js:3`

The file dynamically requires './register' and executes the returned function at import time. While the import path is static and not user-controlled, it does execute code from a sibling module during import, which is a common pattern in utility polyfills but could be leveraged for conditional loading behavior. No obfuscation or external input is used.

### [low] Silent error handling

Finding ID: `NPS-6BA155DEB55C`

File: `optional.js:5`

The catch block silently swallows all exceptions and exports null. This can mask failures or malicious behavior in the 'register' module, making analysis harder, though it is not inherently malicious.

### [low] Top-level execution on import

Finding ID: `NPS-7AFED71E823A`

File: `register.js:2`

The module executes code immediately upon import: module.exports = require('./loader')(global, loadImplementation). This invokes the loader function, which may perform side effects such as auto-detecting and loading promise implementations, potentially requiring various packages. While this is typical for polyfill libraries, it represents import-time execution that could have unintended consequences if the environment is compromised or if the auto-detection loads an unexpected module.

### [low] Install/Import Time Code Execution

Finding ID: `NPS-F63B295A82A6`

File: `register/es6-promise.js:2`

This file executes at import time. It calls require('../register') with a package name and a Promise implementation, which is a known pattern used by libraries like core-js to register/override the global Promise at load time. While this specific usage appears to be a legitimate polyfill registration mechanism, the pattern of modifying global objects during import is a common technique for supply-chain attacks and should be reviewed in the broader context of the '../register' module.

### [low] dynamic module loading / require at import time

Finding ID: `NPS-5A77220D2E2D`

File: `register/when.js:2`

The file calls require('../register') at the top level, which dynamically loads a sibling module and passes a promise implementation object. This is a common pattern in promise polyfill/registration packages, but it executes immediately upon import and relies on a relative path outside the analyzed file. If the parent register module or the 'when' package were compromised, this could serve as an indirect loader. However, no data exfiltration, credential access, obfuscation, shell commands, or network activity is present in this file itself.

## Files reviewed

- `implementation.js` (medium): This one-line redirector invokes code from './register' at import time, hiding the actual implementation and requiring further inspection of that referenced module to confirm safety.
- `index.js` (medium): index.js is a thin wrapper that defers all behavior to an unanalyzed './register' module at import time, requiring inspection of that file to determine intent.
- `optional.js` (medium): The file contains no direct malicious indicators, but dynamically executes a sibling module at import time and silently suppresses errors, which warrants caution and further review of the referenced './register' module.
- `register.js` (medium): The code dynamically requires modules based on input parameters and executes logic at import time, which could pose a medium risk if the implementation parameter is attacker-controlled, but no direct malicious patterns were found.
- `register/es6-promise.js` (medium): This file is a thin shim that registers es6-promise at import time; no direct malicious patterns are present, but it relies on an unanalyzed '../register' module and modifies global state, warranting further review of the referenced file.
- `register/vow.js` (medium): The file is a thin wrapper that dynamically loads a local '../register' module at import time; without inspecting that module, its true behavior and any side effects cannot be verified, warranting caution.
- `register/when.js` (medium): The file is a small top-level module that delegates to a relative register module and the 'when' package; no malicious patterns are evident, but import-time dynamic loading warrants low-severity caution.
- `loader.js` (safe): No malicious patterns detected; the code is a legitimate any-promise registration loader with no network, filesystem, or execution risks.
- `register-shim.js` (safe): No malicious patterns detected
- `register/bluebird.js` (safe): No malicious patterns detected
- `register/lie.js` (safe): This file is a simple Promise implementation registration that requires the local register module and the 'lie' package, with no malicious patterns detected.
- `register/native-promise-only.js` (safe): The file simply registers a promise polyfill module; no malicious patterns detected
- `register/pinkie.js` (safe): No malicious patterns detected
- `register/promise.js` (safe): No malicious patterns detected; the file is a simple registration shim for the 'promise' package.
- `register/q.js` (safe): No malicious patterns detected
- `register/rsvp.js` (safe): No malicious patterns detected; the file simply registers the 'rsvp' Promise implementation with the core-js polyfill loader.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
