Summary
Togoder Security scanned the npm package better-sqlite3@11.10.0 on Oct 4, 2026. An AI review of 14 source files produced 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
File system manipulation outside package scope
NPS-15CFB71B46A5
The script copies files to a destination directory specified via process.argv[2]. If this argument is controlled by an attacker, it could be used to write files outside the intended package scope. However, this is likely intended for build purposes.
Dynamic module loading with computed path
NPS-A8CFA7D8D146
The nativeBinding option allows loading an arbitrary .node addon from a caller-supplied path using path.resolve and a computed require. While this is a documented feature, it permits dynamic native code loading from any path, which could be abused if the option value is attacker-controlled.
SQL injection / unsafe query construction
NPS-6F2D9384F087
The 'source' parameter is interpolated directly into a PRAGMA statement via template literal without sanitization or parameterization. PRAGMA statements cannot use bound parameters in SQLite, but accepting arbitrary strings here allows an attacker to inject additional SQL commands (e.g. attaching databases, altering settings, or chaining statements) if untrusted input reaches this function. This is an injection sink rather than an exfiltration mechanism, but it is a real security weakness.
Potential path traversal
NPS-21FA80ACCB12
The source path is resolved using path.resolve(path.sep, process.argv[3] || path.join(__dirname, 'sqlite3')). If process.argv[3] contains absolute paths or traversal sequences, it could read files from unintended locations. However, this is likely intended for custom builds.
Native addon loading
NPS-63E75A9E99D9
The module loads a native binary (better_sqlite3.node) via bindings at import/construction time. Native addons execute arbitrary machine code and cannot be audited in this JavaScript file; supply-chain integrity of the binary is a trust assumption.
Native addon interaction (cppdb)
NPS-35D28EF766DD
The code accesses this[cppdb] and calls prepare() against a native C++ database binding. While not malicious per se, native addons execute outside the JS sandbox and are a common vector for hidden data access or process spawning that is not visible in this JS file. The behavior of the underlying binding cannot be verified from this snippet alone.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| deps/copy.js | medium | The script performs file copying operations with user-provided paths, which could potentially be exploited for path traversal or unauthorized file writes, but no overtly malicious patterns are present. |
| lib/database.js | medium | This is the legitimate better-sqlite3 Database constructor; no malicious exfiltration, credential harvesting, shell execution, or obfuscation is present, but it dynamically loads native addons and supports an arbitrary nativeBinding path, which are inherent trust/attack-surface concerns. |
| lib/methods/pragma.js | medium | No overt malicious patterns, but the PRAGMA method builds SQL by string interpolation of an unvalidated 'source' argument, creating a SQL injection sink, and relies on an opaque native addon. |
| lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/aggregate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/backup.js | safe | No malicious patterns detected; the code is a legitimate database backup utility that validates inputs, checks directory existence, and asynchronously transfers backup data without any network, credential, or shell access. |
| lib/methods/function.js | safe | No malicious patterns detected; the code is a standard argument validator and binding for native database user-defined functions. |
| lib/methods/inspect.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/serialize.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/table.js | safe | No malicious patterns detected; the code defines a database virtual table API with strict input validation and no external network, filesystem, or process activity. |
| lib/methods/transaction.js | safe | No malicious patterns detected |
| lib/methods/wrappers.js | safe | No malicious patterns detected; the file is a thin, straightforward wrapper exposing native database methods and properties without any of the flagged red flags. |
| lib/sqlite-error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/util.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of better-sqlite3
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 11.10.0 | Needs review | 14 | Oct 4, 2026 |
Frequently asked questions
Is better-sqlite3 safe to use?
No confirmed malware was found in better-sqlite3@11.10.0, but the review flagged 3 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does better-sqlite3 contain malware?
No malware was identified in better-sqlite3@11.10.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was better-sqlite3 checked?
Togoder Security downloaded the published npm package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan better-sqlite3 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in better-sqlite3@11.10.0, cost nothing.