Togoder security

npm package security report

bin-links@6.0.2 security report

Risky patterns found that deserve a look.

Needs review Version 6.0.2 Files reviewed 15 Size 15.1 KB Scanned

Summary

Togoder Security scanned the npm package bin-links@6.0.2 on Oct 6, 2026. An AI review of 15 source files produced 4 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
2
low

Findings 6

medium

File system manipulation outside package scope

NPS-0E03852FC849

The fixBin function accepts an arbitrary file path and will chmod it to 0o777 (minus umask) and potentially rewrite it. If invoked by other package code with paths outside the package (e.g., system binaries or user scripts), it could alter permissions of unrelated files.

lib/fix-bin.js:1
medium

File system manipulation

NPS-41699BEB19E7

The script modifies file permissions with chmod using mode 0o777 (masked by umask) and rewrites bin files to convert Windows line endings to Unix. This changes executable permissions and file contents on the user's system, potentially weakening security if applied broadly.

lib/fix-bin.js:24
medium

File system manipulation outside package scope

NPS-9CB1C89B6ECA

The module links binaries and man pages into system-wide locations when run globally (e.g. {prefix}/bin, {prefix}/share/man) and into node_modules/.bin for local packages. This is expected behavior for a package installer/linker (npm's bin-links), but it modifies files outside the package's own directory, which is a potential security concern if the source or options are untrusted.

lib/index.js
medium

Dynamic module loading / dependency resolution

NPS-20D16BD78B26

The code requires several local modules (./link-bins.js, ./link-mans.js, ./shim-bin.js, ./link-gently.js, ./check-bins.js, ./get-paths.js). These files were not provided for review, so their behavior cannot be verified. In a real audit, these dependencies must be inspected for malicious or obfuscated code.

lib/index.js:1
low

Dependency risk

NPS-D2A74C7E5708

Uses write-file-atomic, which writes to a temporary file and renames it, performing file system operations. While legitimate, it is a third-party dependency that could itself be compromised; combined with the chmod logic, it increases the attack surface for local file tampering.

lib/fix-bin.js:7
low

Global install path modification

NPS-D78C2B874E3B

When 'top' and 'global' are true, binaries may be installed into system prefix directories. This grants elevated privilege effects if run with sufficient permissions, but no explicit privilege escalation or shell execution is present in the provided file.

lib/index.js:15

Files reviewed

FileVerdictWhat the reviewer saw
lib/fix-bin.js medium The code is a legitimate utility for fixing executable permissions and hashbang line endings, but its broad chmod and file-rewrite behavior on arbitrary paths presents a moderate security risk if misused or invoked with untrusted input.
lib/index.js medium This file is likely npm's bin-links module and contains no explicit malicious patterns, but it performs system-level file linking and relies on unaudited local modules, warranting caution.
lib/bin-target.js safe Cleared by Jev triage; no further analysis needed
lib/check-bin.js safe No malicious patterns detected
lib/check-bins.js safe No malicious patterns detected; the module only performs package bin conflict checking via local helper functions.
lib/get-node-modules.js safe Cleared by Jev triage; no further analysis needed
lib/get-paths.js safe Cleared by Jev triage; no further analysis needed
lib/get-prefix.js safe Cleared by Jev triage; no further analysis needed
lib/is-windows.js safe No malicious patterns detected
lib/link-bin.js safe No malicious patterns detected
lib/link-bins.js safe No malicious patterns detected
lib/link-gently.js safe No malicious patterns detected; the code performs benign symlink management for package binaries and manpages with no network, credential, or code-execution behavior.
lib/link-mans.js safe No malicious patterns detected; the code performs legitimate man page link management with proper path sanitization and validation.
lib/man-target.js safe Cleared by Jev triage; no further analysis needed
lib/shim-bin.js safe This npm bin shim utility contains no malicious patterns; it only uses standard path/fs modules and well-known shim libraries to create command shims, with no network, credential, or dynamic-execution behavior.

Frequently asked questions

Is bin-links safe to use?

No confirmed malware was found in bin-links@6.0.2, but the review flagged 4 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does bin-links contain malware?

No malware was identified in bin-links@6.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was bin-links checked?

Togoder Security downloaded the published npm package and had an AI model read its 15 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan bin-links together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in bin-links@6.0.2, cost nothing.

Related security reports