Summary
Togoder Security scanned the npm package browserslist@4.28.9 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Dynamic module loading with computed input
NPS-8B833FCA6B46
loadQueries uses require(require.resolve(name, { paths: ['.', ctx.path] })) where name comes from external configuration/environment; this allows arbitrary module resolution and execution. Although checkExtend applies restrictive regex patterns and can be bypassed via dangerousExtend or BROWSERSLIST_DANGEROUS_EXTEND env var, it is still a dynamic require of external input.
Dynamic require based on sanitized input
NPS-8B14D17F2748
loadCountry and loadFeature perform require('caniuse-lite/data/regions/' + code + '.js') and require('caniuse-lite/data/features/' + name + '.js') after stripping non-word/non-dash characters; path traversal is mitigated by the regex but still constitutes computed dynamic module loading.
File system access outside package scope
NPS-D1C50838406D
Functions read package.json, browserslist, .browserslistrc, and browserslist-stats.json files from parent directories up to BROWSERSLIST_ROOT_PATH (or filesystem root). readConfig/parsePackage read arbitrary user-specified config paths via opts.config or BROWSERSLIST_CONFIG.
Environment variable harvesting
NPS-2512E7C19589
Multiple process.env variables are read (BROWSERSLIST, BROWSERSLIST_CONFIG, BROWSERSLIST_ENV, BROWSERSLIST_STATS, BROWSERSLIST_ROOT_PATH, NODE_ENV, etc.), and module.exports.env exposes process.env directly. This is standard configuration behavior but exposes environment state and can be abused if the object is leaked.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| node.js | medium | The code is a legitimate browserslist configuration loader but contains several dynamic require calls and broad environment/filesystem reads that could be abused if attacker-controlled inputs reach these functions. |
| browser.js | safe | Cleared by Jev triage; no further analysis needed |
| cli.js | safe | Standard browserslist CLI implementation with no malicious patterns detected; it reads local config/stats files and prints query results, only performing a deprecation-triggered DB update via the legitimate update-browserslist-db dependency. |
| error.js | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | No malicious patterns detected; the code is a standard browserslist query parser with only static requires and no network, filesystem, or process execution activity. |
| parse.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is browserslist safe to use?
No confirmed malware was found in browserslist@4.28.9, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does browserslist contain malware?
No malware was identified in browserslist@4.28.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was browserslist checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan browserslist together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in browserslist@4.28.9, cost nothing.