Summary
Togoder Security scanned the npm package commander@14.0.0 on Oct 4, 2026. An AI review of 8 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 4
child_process.spawn usage
NPS-F80E907CEC72
The code spawns child processes to execute subcommands (executable files or node) using childProcess.spawn. This is expected functionality of the Commander CLI library and is gated behind user-defined subcommands. No malicious intent observed; args are derived from parsed CLI input, not from external untrusted sources.
process.exit calls
NPS-B076DF1D8A90
The code calls process.exit in various error/help flows. This is normal CLI library behavior, not a security concern.
environment variable access
NPS-466BB8800C5B
The code reads NO_COLOR, FORCE_COLOR, CLICOLOR_FORCE for color detection, and supports option.envVar for reading configured env vars. These are standard, documented behaviors, not credential harvesting.
fs.existsSync / fs.realpathSync
NPS-791EDF3549AF
File system checks are used to locate executable subcommands relative to the script path and to check for missing mandatory options. Scoped to expected CLI use, no exfiltration or writes outside package scope.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm.mjs | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/argument.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/command.js | safe | This is the legitimate Commander.js CLI library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or unauthorized code execution were detected. |
| lib/error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/help.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/suggestSimilar.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 5 scanned versions of commander are flagged high or critical. The latest scanned version, 15.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 15.0.0 | Needs review | 1 | 15.0.0 | |
| 14.0.2 – 14.0.3 | Not scanned | 2 | >=14.0.2 <=14.0.3 | |
| 14.0.1 | Needs review | 1 | 14.0.1 | process spawning |
| 14.0.0 | No issues | 1 | 14.0.0 | |
| 13.1.0 | Not scanned | 1 | 13.1.0 | |
| 12.1.0 | No issues | 1 | 12.1.0 | |
| 3.0.2 – 10.0.1 | Not scanned | 8 | >=3.0.2 <=10.0.1 | |
| 2.20.3 | Needs review | 1 | 2.20.3 | process_spawning |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of commander
Frequently asked questions
Is commander safe to use?
Our AI source review of commander@14.0.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does commander contain malware?
No malware was identified in commander@14.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was commander checked?
Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan commander together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in commander@14.0.0, cost nothing.