Summary
Togoder Security scanned the npm package busboy@1.6.0 on Oct 4, 2026. An AI review of 11 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Monkey-patching internal methods
NPS-3DD86418C75E
The multiparty case hijacks internal methods (onParseHeaderField, onParseHeaderValue, etc.) to count calls. This is a benchmark instrumentation technique and not a security issue in itself, but demonstrates a pattern of overriding library internals.
Resource exhaustion / DoS potential
NPS-9079FA8818C7
The benchmark creates 100 multipart file parts of 1 MB each (100 MB total) and sets parser limits to Infinity (fieldSizeLimit, maxFieldsSize, maxFields, maxFilesSize). This is intentionally benchmarking performance, but if such code were used in a production context it would allow unbounded resource consumption. In a benchmark file it is expected, so risk is low in context.
Dynamic module loading from command-line input
NPS-1088267CC5BB
The script uses process.argv[2] as the module name to require() from a fixed allowlist (busboy, formidable, multiparty). The allowlist prevents arbitrary module loading, so risk is low, but still worth noting as a pattern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bench/bench-multipart-files-100mb-small.js | medium | The file is a legitimate multipart parser benchmark with no malicious behavior; findings are limited to intentional unbounded limits and internal method hijacking used for benchmarking, not exploitation. |
| .eslintrc.js | safe | Cleared by Jev triage; no further analysis needed |
| bench/bench-multipart-fields-100mb-big.js | safe | The file is a legitimate multipart parser benchmark script with no malicious behavior, network activity, or filesystem manipulation. |
| bench/bench-multipart-fields-100mb-small.js | safe | This is a benchmark script for comparing multipart parsers with no malicious patterns detected. |
| bench/bench-multipart-files-100mb-big.js | safe | This is a legitimate multipart parsing benchmark script with no malicious patterns detected. |
| bench/bench-urlencoded-fields-100pairs-small.js | safe | This is a benchmark script for comparing URL-encoded form parsers; it only reads process.argv and requires known parser modules, with no malicious patterns. |
| bench/bench-urlencoded-fields-900pairs-small-alt.js | safe | No malicious patterns detected; this is a legitimate benchmark script for comparing URL-encoded form parsers. |
| lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/types/multipart.js | safe | No malicious patterns detected in this multipart form-data parser implementation. |
| lib/types/urlencoded.js | safe | No malicious patterns detected; the code is a standard URL-encoded form parser with no network, filesystem, process, or obfuscated behavior. |
| lib/utils.js | safe | No malicious patterns detected; the file contains standard HTTP content-type and disposition parsing utilities with no network, filesystem, process, or dynamic code execution activity. |
Frequently asked questions
Is busboy safe to use?
No confirmed malware was found in busboy@1.6.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does busboy contain malware?
No malware was identified in busboy@1.6.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was busboy checked?
Togoder Security downloaded the published npm package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan busboy together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in busboy@1.6.0, cost nothing.