Togoder security

npm package security report

async-function@1.0.0 security report

Risky patterns found that deserve a look.

Needs review Version 1.0.0 Files reviewed 4 Size 872 B Scanned

Summary

Togoder Security scanned the npm package async-function@1.0.0 on Oct 6, 2026. An AI review of 4 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
1
low

Findings 2

medium

Dynamic code execution capability

NPS-398506B44AC3

The code extracts the AsyncFunction constructor via 'async function () {}.constructor'. This constructor is equivalent to 'new Function(...)' and can compile and execute arbitrary JavaScript strings at runtime. While the file does not itself call it with dynamic input, exporting this constructor allows any consumer (or later injected code) to perform dynamic code execution, which is a common evasion/backdoor primitive. The comment also references 'no-empty-function' and uses type imports, indicating this is a deliberately exposed eval-like capability.

index.js:4
low

Dynamic code execution

NPS-055D5F731DF4

Uses the Function constructor to dynamically create and execute code ('return async function () {}') to detect async function support. While not inherently malicious, this pattern can be abused for code execution if the input were ever tainted. Here the input is static and safe, but the pattern is a red flag in third-party packages.

legacy.js:11

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The module is a wrapper that exports the AsyncFunction constructor (equivalent to eval/new Function), providing a dynamic code execution primitive to any importer.
legacy.js medium Uses dynamic code execution via Function constructor for feature detection, but contains no malicious behavior; flagged as a cautionary pattern only.
index.mjs safe Cleared by Jev triage; no further analysis needed
require.mjs safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is async-function safe to use?

No confirmed malware was found in async-function@1.0.0, but the review flagged 1 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does async-function contain malware?

No malware was identified in async-function@1.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was async-function checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan async-function together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in async-function@1.0.0, cost nothing.

Related security reports