# bindings@1.5.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:21:40.000Z
- Files reviewed: 1
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/bindings
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package bindings@1.5.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic module loading

Finding ID: `NPS-B7FA565C7D08`

File: `bindings.js`

The bindings() function dynamically loads native .node addon files from multiple computed paths using require(). While this is the intended purpose of the 'bindings' package (a well-known legitimate npm package), dynamic loading of native binaries from computed filesystem paths can be abused if an attacker can place a malicious .node file in a searched directory (e.g., build/Release, compiled/<version>/<platform>/<arch>, lib/binding/<nodePreGyp>).

### [low] filesystem probing outside package scope

Finding ID: `NPS-DFE3241DB1C9`

File: `bindings.js`

getRoot() walks up the directory tree reading package.json/node_modules existence checks until reaching filesystem root or cwd. This traverses parent directories above the package, which is expected behavior for locating a module root but expands the search surface for loading arbitrary native modules.

### [low] stack trace introspection

Finding ID: `NPS-86464722F407`

File: `bindings.js`

getFileName() temporarily overrides Error.prepareStackTrace and Error.stackTraceLimit to inspect the call stack and derive the invoking module's filename. This is used to compute module_root and is a known technique in the legitimate 'bindings' package, but stack introspection can be used to fingerprint the host environment.

## Files reviewed

- `bindings.js` (medium): This is the well-known legitimate 'bindings' package that dynamically requires native .node addon files; no exfiltration, obfuscation, or malicious payloads are present, though dynamic native module loading and parent-directory traversal warrant caution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
