Summary
Togoder Security scanned the npm package bindings@1.5.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
dynamic module loading
NPS-B7FA565C7D08
The bindings() function dynamically loads native .node addon files from multiple computed paths using require(). While this is the intended purpose of the 'bindings' package (a well-known legitimate npm package), dynamic loading of native binaries from computed filesystem paths can be abused if an attacker can place a malicious .node file in a searched directory (e.g., build/Release, compiled/<version>/<platform>/<arch>, lib/binding/<nodePreGyp>).
filesystem probing outside package scope
NPS-DFE3241DB1C9
getRoot() walks up the directory tree reading package.json/node_modules existence checks until reaching filesystem root or cwd. This traverses parent directories above the package, which is expected behavior for locating a module root but expands the search surface for loading arbitrary native modules.
stack trace introspection
NPS-86464722F407
getFileName() temporarily overrides Error.prepareStackTrace and Error.stackTraceLimit to inspect the call stack and derive the invoking module's filename. This is used to compute module_root and is a known technique in the legitimate 'bindings' package, but stack introspection can be used to fingerprint the host environment.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bindings.js | medium | This is the well-known legitimate 'bindings' package that dynamically requires native .node addon files; no exfiltration, obfuscation, or malicious payloads are present, though dynamic native module loading and parent-directory traversal warrant caution. |
Frequently asked questions
Is bindings safe to use?
No confirmed malware was found in bindings@1.5.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does bindings contain malware?
No malware was identified in bindings@1.5.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was bindings checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan bindings together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in bindings@1.5.0, cost nothing.