Summary
Togoder Security scanned the npm package commander@14.0.1 on Oct 4, 2026. An AI review of 8 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
process spawning
NPS-D1EA9055727B
The file uses child_process.spawn to execute subcommands and external binaries. While this is a legitimate feature of the Commander.js CLI library for running executable subcommands, it is a dual-use pattern that could be abused if the subcommand name or executable path is derived from untrusted input. In this library the executable name and directory are typically controlled by the package author, but the capability warrants attention.
file system access
NPS-BACFE47B8C2A
fs.existsSync and fs.realpathSync are used to locate executable subcommand files relative to the script directory. No access to sensitive files such as .npmrc, .ssh, .aws, or browser profiles occurs.
dynamic process execution via Node.js
NPS-B2E38C01A348
childProcess.spawn is called with process.argv[0] (the Node.js executable) and process.execPath along with arguments that include the executable file path and user-supplied operands. This is standard CLI subcommand dispatch behavior, not obfuscated or hidden, and does not exfiltrate data. It does not execute arbitrary code from environment variables or remote sources.
environment variable usage
NPS-5A5FCC0FA6A4
_parseOptionsEnv reads process.env[option.envVar] for options that explicitly declare an envVar, and useColor reads NO_COLOR/FORCE_COLOR/CLICOLOR_FORCE. These are expected CLI conventions, not credential harvesting.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/command.js | medium | This is the legitimate Commander.js CLI library; it spawns subprocesses for executable subcommands (expected behavior) but contains no data exfiltration, credential harvesting, obfuscation, backdoors, or malicious install-time code. |
| esm.mjs | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/argument.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/help.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/suggestSimilar.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 5 scanned versions of commander are flagged high or critical. The latest scanned version, 15.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 15.0.0 | Needs review | 1 | 15.0.0 | |
| 14.0.2 – 14.0.3 | Not scanned | 2 | >=14.0.2 <=14.0.3 | |
| 14.0.1 | Needs review | 1 | 14.0.1 | process spawning |
| 14.0.0 | No issues | 1 | 14.0.0 | |
| 13.1.0 | Not scanned | 1 | 13.1.0 | |
| 12.1.0 | No issues | 1 | 12.1.0 | |
| 3.0.2 – 10.0.1 | Not scanned | 8 | >=3.0.2 <=10.0.1 | |
| 2.20.3 | Needs review | 1 | 2.20.3 | process_spawning |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of commander
Frequently asked questions
Is commander safe to use?
No confirmed malware was found in commander@14.0.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does commander contain malware?
No malware was identified in commander@14.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was commander checked?
Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan commander together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in commander@14.0.1, cost nothing.