Togoder security

npm package security report

commander@14.0.1 security report

Risky patterns found that deserve a look.

Needs review Version 14.0.1 Files reviewed 8 Size 123.9 KB Scanned

Summary

Togoder Security scanned the npm package commander@14.0.1 on Oct 4, 2026. An AI review of 8 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

process spawning

NPS-D1EA9055727B

The file uses child_process.spawn to execute subcommands and external binaries. While this is a legitimate feature of the Commander.js CLI library for running executable subcommands, it is a dual-use pattern that could be abused if the subcommand name or executable path is derived from untrusted input. In this library the executable name and directory are typically controlled by the package author, but the capability warrants attention.

lib/command.js:629
low

file system access

NPS-BACFE47B8C2A

fs.existsSync and fs.realpathSync are used to locate executable subcommand files relative to the script directory. No access to sensitive files such as .npmrc, .ssh, .aws, or browser profiles occurs.

lib/command.js:594
low

dynamic process execution via Node.js

NPS-B2E38C01A348

childProcess.spawn is called with process.argv[0] (the Node.js executable) and process.execPath along with arguments that include the executable file path and user-supplied operands. This is standard CLI subcommand dispatch behavior, not obfuscated or hidden, and does not exfiltrate data. It does not execute arbitrary code from environment variables or remote sources.

lib/command.js:634
low

environment variable usage

NPS-5A5FCC0FA6A4

_parseOptionsEnv reads process.env[option.envVar] for options that explicitly declare an envVar, and useColor reads NO_COLOR/FORCE_COLOR/CLICOLOR_FORCE. These are expected CLI conventions, not credential harvesting.

lib/command.js:1247

Files reviewed

FileVerdictWhat the reviewer saw
lib/command.js medium This is the legitimate Commander.js CLI library; it spawns subprocesses for executable subcommands (expected behavior) but contains no data exfiltration, credential harvesting, obfuscation, backdoors, or malicious install-time code.
esm.mjs safe Cleared by Jev triage; no further analysis needed
index.js safe Cleared by Jev triage; no further analysis needed
lib/argument.js safe Cleared by Jev triage; no further analysis needed
lib/error.js safe Cleared by Jev triage; no further analysis needed
lib/help.js safe Cleared by Jev triage; no further analysis needed
lib/option.js safe Cleared by Jev triage; no further analysis needed
lib/suggestSimilar.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 5 scanned versions of commander are flagged high or critical. The latest scanned version, 15.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.20.315.0.0
VersionsVerdictCountRangeTop findings
15.0.0 Needs review 1 15.0.0
14.0.2 – 14.0.3 Not scanned 2 >=14.0.2 <=14.0.3
14.0.1 Needs review 1 14.0.1 process spawning
14.0.0 No issues 1 14.0.0
13.1.0 Not scanned 1 13.1.0
12.1.0 No issues 1 12.1.0
3.0.2 – 10.0.1 Not scanned 8 >=3.0.2 <=10.0.1
2.20.3 Needs review 1 2.20.3 process_spawning

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of commander

VersionVerdictFilesScanned
15.0.0 Needs review 7 Oct 6, 2026
14.0.1 Needs review 8 Oct 4, 2026
14.0.0 No issues 8 Oct 4, 2026
12.1.0 No issues 8 May 15, 2026
2.20.3 Needs review 1 Oct 4, 2026

Frequently asked questions

Is commander safe to use?

No confirmed malware was found in commander@14.0.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does commander contain malware?

No malware was identified in commander@14.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was commander checked?

Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan commander together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in commander@14.0.1, cost nothing.

Related security reports