Togoder security

npm package security report

bindings npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.5.0 Files reviewed 1 Size 5.8 KB Scanned

Summary

Togoder Security scanned the npm package bindings@1.5.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

dynamic module loading

NPS-B7FA565C7D08

The bindings() function dynamically loads native .node addon files from multiple computed paths using require(). While this is the intended purpose of the 'bindings' package (a well-known legitimate npm package), dynamic loading of native binaries from computed filesystem paths can be abused if an attacker can place a malicious .node file in a searched directory (e.g., build/Release, compiled/<version>/<platform>/<arch>, lib/binding/<nodePreGyp>).

bindings.js
low

filesystem probing outside package scope

NPS-DFE3241DB1C9

getRoot() walks up the directory tree reading package.json/node_modules existence checks until reaching filesystem root or cwd. This traverses parent directories above the package, which is expected behavior for locating a module root but expands the search surface for loading arbitrary native modules.

bindings.js
low

stack trace introspection

NPS-86464722F407

getFileName() temporarily overrides Error.prepareStackTrace and Error.stackTraceLimit to inspect the call stack and derive the invoking module's filename. This is used to compute module_root and is a known technique in the legitimate 'bindings' package, but stack introspection can be used to fingerprint the host environment.

bindings.js

Files reviewed

FileVerdictWhat the reviewer saw
bindings.js medium This is the well-known legitimate 'bindings' package that dynamically requires native .node addon files; no exfiltration, obfuscation, or malicious payloads are present, though dynamic native module loading and parent-directory traversal warrant caution.

Scanned versions of bindings

VersionVerdictFilesScanned
1.5.0 Needs review 1 Oct 4, 2026

Frequently asked questions

Is bindings safe to use?

No confirmed malware was found in bindings@1.5.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does bindings contain malware?

No malware was identified in bindings@1.5.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was bindings checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan bindings together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in bindings@1.5.0, cost nothing.

Related security reports