Togoder security

npm package security report

busboy@1.6.0 security report

Risky patterns found that deserve a look.

Needs review Version 1.6.0 Files reviewed 11 Size 63.1 KB Scanned

Summary

Togoder Security scanned the npm package busboy@1.6.0 on Oct 4, 2026. An AI review of 11 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Monkey-patching internal methods

NPS-3DD86418C75E

The multiparty case hijacks internal methods (onParseHeaderField, onParseHeaderValue, etc.) to count calls. This is a benchmark instrumentation technique and not a security issue in itself, but demonstrates a pattern of overriding library internals.

bench/bench-multipart-files-100mb-small.js
low

Resource exhaustion / DoS potential

NPS-9079FA8818C7

The benchmark creates 100 multipart file parts of 1 MB each (100 MB total) and sets parser limits to Infinity (fieldSizeLimit, maxFieldsSize, maxFields, maxFilesSize). This is intentionally benchmarking performance, but if such code were used in a production context it would allow unbounded resource consumption. In a benchmark file it is expected, so risk is low in context.

bench/bench-multipart-files-100mb-small.js:8
low

Dynamic module loading from command-line input

NPS-1088267CC5BB

The script uses process.argv[2] as the module name to require() from a fixed allowlist (busboy, formidable, multiparty). The allowlist prevents arbitrary module loading, so risk is low, but still worth noting as a pattern.

bench/bench-multipart-files-100mb-small.js:47

Files reviewed

FileVerdictWhat the reviewer saw
bench/bench-multipart-files-100mb-small.js medium The file is a legitimate multipart parser benchmark with no malicious behavior; findings are limited to intentional unbounded limits and internal method hijacking used for benchmarking, not exploitation.
.eslintrc.js safe Cleared by Jev triage; no further analysis needed
bench/bench-multipart-fields-100mb-big.js safe The file is a legitimate multipart parser benchmark script with no malicious behavior, network activity, or filesystem manipulation.
bench/bench-multipart-fields-100mb-small.js safe This is a benchmark script for comparing multipart parsers with no malicious patterns detected.
bench/bench-multipart-files-100mb-big.js safe This is a legitimate multipart parsing benchmark script with no malicious patterns detected.
bench/bench-urlencoded-fields-100pairs-small.js safe This is a benchmark script for comparing URL-encoded form parsers; it only reads process.argv and requires known parser modules, with no malicious patterns.
bench/bench-urlencoded-fields-900pairs-small-alt.js safe No malicious patterns detected; this is a legitimate benchmark script for comparing URL-encoded form parsers.
lib/index.js safe Cleared by Jev triage; no further analysis needed
lib/types/multipart.js safe No malicious patterns detected in this multipart form-data parser implementation.
lib/types/urlencoded.js safe No malicious patterns detected; the code is a standard URL-encoded form parser with no network, filesystem, process, or obfuscated behavior.
lib/utils.js safe No malicious patterns detected; the file contains standard HTTP content-type and disposition parsing utilities with no network, filesystem, process, or dynamic code execution activity.

Frequently asked questions

Is busboy safe to use?

No confirmed malware was found in busboy@1.6.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does busboy contain malware?

No malware was identified in busboy@1.6.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was busboy checked?

Togoder Security downloaded the published npm package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan busboy together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in busboy@1.6.0, cost nothing.

Related security reports