Summary
Togoder Security scanned the npm package bin-links@6.0.2 on Oct 6, 2026. An AI review of 15 source files produced 4 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
File system manipulation outside package scope
NPS-0E03852FC849
The fixBin function accepts an arbitrary file path and will chmod it to 0o777 (minus umask) and potentially rewrite it. If invoked by other package code with paths outside the package (e.g., system binaries or user scripts), it could alter permissions of unrelated files.
File system manipulation
NPS-41699BEB19E7
The script modifies file permissions with chmod using mode 0o777 (masked by umask) and rewrites bin files to convert Windows line endings to Unix. This changes executable permissions and file contents on the user's system, potentially weakening security if applied broadly.
File system manipulation outside package scope
NPS-9CB1C89B6ECA
The module links binaries and man pages into system-wide locations when run globally (e.g. {prefix}/bin, {prefix}/share/man) and into node_modules/.bin for local packages. This is expected behavior for a package installer/linker (npm's bin-links), but it modifies files outside the package's own directory, which is a potential security concern if the source or options are untrusted.
Dynamic module loading / dependency resolution
NPS-20D16BD78B26
The code requires several local modules (./link-bins.js, ./link-mans.js, ./shim-bin.js, ./link-gently.js, ./check-bins.js, ./get-paths.js). These files were not provided for review, so their behavior cannot be verified. In a real audit, these dependencies must be inspected for malicious or obfuscated code.
Dependency risk
NPS-D2A74C7E5708
Uses write-file-atomic, which writes to a temporary file and renames it, performing file system operations. While legitimate, it is a third-party dependency that could itself be compromised; combined with the chmod logic, it increases the attack surface for local file tampering.
Global install path modification
NPS-D78C2B874E3B
When 'top' and 'global' are true, binaries may be installed into system prefix directories. This grants elevated privilege effects if run with sufficient permissions, but no explicit privilege escalation or shell execution is present in the provided file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/fix-bin.js | medium | The code is a legitimate utility for fixing executable permissions and hashbang line endings, but its broad chmod and file-rewrite behavior on arbitrary paths presents a moderate security risk if misused or invoked with untrusted input. |
| lib/index.js | medium | This file is likely npm's bin-links module and contains no explicit malicious patterns, but it performs system-level file linking and relies on unaudited local modules, warranting caution. |
| lib/bin-target.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/check-bin.js | safe | No malicious patterns detected |
| lib/check-bins.js | safe | No malicious patterns detected; the module only performs package bin conflict checking via local helper functions. |
| lib/get-node-modules.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/get-paths.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/get-prefix.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/is-windows.js | safe | No malicious patterns detected |
| lib/link-bin.js | safe | No malicious patterns detected |
| lib/link-bins.js | safe | No malicious patterns detected |
| lib/link-gently.js | safe | No malicious patterns detected; the code performs benign symlink management for package binaries and manpages with no network, credential, or code-execution behavior. |
| lib/link-mans.js | safe | No malicious patterns detected; the code performs legitimate man page link management with proper path sanitization and validation. |
| lib/man-target.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/shim-bin.js | safe | This npm bin shim utility contains no malicious patterns; it only uses standard path/fs modules and well-known shim libraries to create command shims, with no network, credential, or dynamic-execution behavior. |
Frequently asked questions
Is bin-links safe to use?
No confirmed malware was found in bin-links@6.0.2, but the review flagged 4 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does bin-links contain malware?
No malware was identified in bin-links@6.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was bin-links checked?
Togoder Security downloaded the published npm package and had an AI model read its 15 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan bin-links together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in bin-links@6.0.2, cost nothing.