Summary
Togoder Security scanned the npm package async-function@1.0.0 on Oct 6, 2026. An AI review of 4 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Dynamic code execution capability
NPS-398506B44AC3
The code extracts the AsyncFunction constructor via 'async function () {}.constructor'. This constructor is equivalent to 'new Function(...)' and can compile and execute arbitrary JavaScript strings at runtime. While the file does not itself call it with dynamic input, exporting this constructor allows any consumer (or later injected code) to perform dynamic code execution, which is a common evasion/backdoor primitive. The comment also references 'no-empty-function' and uses type imports, indicating this is a deliberately exposed eval-like capability.
Dynamic code execution
NPS-055D5F731DF4
Uses the Function constructor to dynamically create and execute code ('return async function () {}') to detect async function support. While not inherently malicious, this pattern can be abused for code execution if the input were ever tainted. Here the input is static and safe, but the pattern is a red flag in third-party packages.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | The module is a wrapper that exports the AsyncFunction constructor (equivalent to eval/new Function), providing a dynamic code execution primitive to any importer. |
| legacy.js | medium | Uses dynamic code execution via Function constructor for feature detection, but contains no malicious behavior; flagged as a cautionary pattern only. |
| index.mjs | safe | Cleared by Jev triage; no further analysis needed |
| require.mjs | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is async-function safe to use?
No confirmed malware was found in async-function@1.0.0, but the review flagged 1 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does async-function contain malware?
No malware was identified in async-function@1.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was async-function checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan async-function together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in async-function@1.0.0, cost nothing.