# async-function@1.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:13:54.000Z
- Files reviewed: 4
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/async-function
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package async-function@1.0.0 on Oct 6, 2026. An AI review of 4 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution capability

Finding ID: `NPS-398506B44AC3`

File: `index.js:4`

The code extracts the AsyncFunction constructor via 'async function () {}.constructor'. This constructor is equivalent to 'new Function(...)' and can compile and execute arbitrary JavaScript strings at runtime. While the file does not itself call it with dynamic input, exporting this constructor allows any consumer (or later injected code) to perform dynamic code execution, which is a common evasion/backdoor primitive. The comment also references 'no-empty-function' and uses type imports, indicating this is a deliberately exposed eval-like capability.

### [low] Dynamic code execution

Finding ID: `NPS-055D5F731DF4`

File: `legacy.js:11`

Uses the Function constructor to dynamically create and execute code ('return async function () {}') to detect async function support. While not inherently malicious, this pattern can be abused for code execution if the input were ever tainted. Here the input is static and safe, but the pattern is a red flag in third-party packages.

## Files reviewed

- `index.js` (medium): The module is a wrapper that exports the AsyncFunction constructor (equivalent to eval/new Function), providing a dynamic code execution primitive to any importer.
- `legacy.js` (medium): Uses dynamic code execution via Function constructor for feature detection, but contains no malicious behavior; flagged as a cautionary pattern only.
- `index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `require.mjs` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
