Togoder security

npm package security report

array-includes npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 3.1.9 Files reviewed 5 Size 2.7 KB Scanned

Summary

Togoder Security scanned the npm package array-includes@3.1.9 on Oct 6, 2026. An AI review of 5 source files produced 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
0
low

Findings 3

medium

Indirect code execution via module import

NPS-161B52F6FCA8

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

auto.js:3
medium

Potential global environment modification

NPS-69A1E6118607

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

auto.js:3
medium

Opaque dependency

NPS-289CF45BDF72

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

auto.js:3

Files reviewed

FileVerdictWhat the reviewer saw
auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
implementation.js safe No malicious patterns detected; the code is a legitimate polyfill implementation for Array.prototype.includes with standard dependencies.
index.js safe No malicious patterns detected
polyfill.js safe Cleared by Jev triage; no further analysis needed
shim.js safe No malicious patterns detected

Scanned versions of array-includes

VersionVerdictFilesScanned
3.1.9 Needs review 5 Oct 6, 2026

Frequently asked questions

Is array-includes safe to use?

No confirmed malware was found in array-includes@3.1.9, but the review flagged 3 medium severity findings for risky patterns worth checking before you rely on it.

Does array-includes contain malware?

No malware was identified in array-includes@3.1.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was array-includes checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan array-includes together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in array-includes@3.1.9, cost nothing.

Related security reports