Togoder security

npm package security report

browserslist@4.28.9 security report

Risky patterns found that deserve a look.

Needs review Version 4.28.9 Files reviewed 6 Size 60.4 KB Scanned

Summary

Togoder Security scanned the npm package browserslist@4.28.9 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

Dynamic module loading with computed input

NPS-8B833FCA6B46

loadQueries uses require(require.resolve(name, { paths: ['.', ctx.path] })) where name comes from external configuration/environment; this allows arbitrary module resolution and execution. Although checkExtend applies restrictive regex patterns and can be bypassed via dangerousExtend or BROWSERSLIST_DANGEROUS_EXTEND env var, it is still a dynamic require of external input.

node.js:212
low

Dynamic require based on sanitized input

NPS-8B14D17F2748

loadCountry and loadFeature perform require('caniuse-lite/data/regions/' + code + '.js') and require('caniuse-lite/data/features/' + name + '.js') after stripping non-word/non-dash characters; path traversal is mitigated by the regex but still constitutes computed dynamic module loading.

node.js:283
low

File system access outside package scope

NPS-D1C50838406D

Functions read package.json, browserslist, .browserslistrc, and browserslist-stats.json files from parent directories up to BROWSERSLIST_ROOT_PATH (or filesystem root). readConfig/parsePackage read arbitrary user-specified config paths via opts.config or BROWSERSLIST_CONFIG.

node.js:322
low

Environment variable harvesting

NPS-2512E7C19589

Multiple process.env variables are read (BROWSERSLIST, BROWSERSLIST_CONFIG, BROWSERSLIST_ENV, BROWSERSLIST_STATS, BROWSERSLIST_ROOT_PATH, NODE_ENV, etc.), and module.exports.env exposes process.env directly. This is standard configuration behavior but exposes environment state and can be abused if the object is leaked.

node.js:341

Files reviewed

FileVerdictWhat the reviewer saw
node.js medium The code is a legitimate browserslist configuration loader but contains several dynamic require calls and broad environment/filesystem reads that could be abused if attacker-controlled inputs reach these functions.
browser.js safe Cleared by Jev triage; no further analysis needed
cli.js safe Standard browserslist CLI implementation with no malicious patterns detected; it reads local config/stats files and prints query results, only performing a deprecation-triggered DB update via the legitimate update-browserslist-db dependency.
error.js safe Cleared by Jev triage; no further analysis needed
index.js safe No malicious patterns detected; the code is a standard browserslist query parser with only static requires and no network, filesystem, or process execution activity.
parse.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is browserslist safe to use?

No confirmed malware was found in browserslist@4.28.9, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does browserslist contain malware?

No malware was identified in browserslist@4.28.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was browserslist checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan browserslist together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in browserslist@4.28.9, cost nothing.

Related security reports