Togoder security

npm package security report

commander@2.20.3 security report

Risky patterns found that deserve a look.

Needs review Version 2.20.3 Files reviewed 1 Size 27.2 KB Scanned

Summary

Togoder Security scanned the npm package commander@2.20.3 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

process_spawning

NPS-D78A72987449

The module uses child_process.spawn() to execute subcommands. The bin name is constructed from argv[1] and args[0] passed by the caller, and resolved via fs.realpathSync before spawning. While this is typical for CLI frameworks (this is commander.js), the spawn target is partially influenced by user-provided arguments. In a normally-installed commander package this is expected behavior, but if argv is attacker-controlled it could lead to execution of arbitrary local binaries matching the constructed name.

index.js:557
low

dynamic_module_loading

NPS-610904D9622D

This file is the main entry (index.js) of what appears to be commander.js. It executes top-level code on require: it instantiates a root Command, registers constructors, and sets up EventEmitter inheritance. No obfuscation, eval, network calls, or credential harvesting are present.

index.js:22
low

file_system_access

NPS-B0313CEBF053

Uses fs.realpathSync, fs.statSync, and path manipulation on resolved binary paths to locate and execute local executables relative to the invoking script. Legitimate for commander but worth noting as filesystem interaction beyond package scope.

index.js:545

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium This is the legitimate commander.js CLI framework; it spawns subcommand executables and performs local filesystem lookups, but contains no exfiltration, obfuscation, credential harvesting, or backdoor patterns.

Affected version ranges

None of the 5 scanned versions of commander are flagged high or critical. The latest scanned version, 15.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.20.315.0.0
VersionsVerdictCountRangeTop findings
15.0.0 Needs review 1 15.0.0
14.0.2 – 14.0.3 Not scanned 2 >=14.0.2 <=14.0.3
14.0.1 Needs review 1 14.0.1 process spawning
14.0.0 No issues 1 14.0.0
13.1.0 Not scanned 1 13.1.0
12.1.0 No issues 1 12.1.0
3.0.2 – 10.0.1 Not scanned 8 >=3.0.2 <=10.0.1
2.20.3 Needs review 1 2.20.3 process_spawning

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of commander

VersionVerdictFilesScanned
15.0.0 Needs review 7 Oct 6, 2026
14.0.1 Needs review 8 Oct 4, 2026
14.0.0 No issues 8 Oct 4, 2026
12.1.0 No issues 8 May 15, 2026
2.20.3 Needs review 1 Oct 4, 2026

Frequently asked questions

Is commander safe to use?

No confirmed malware was found in commander@2.20.3, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does commander contain malware?

No malware was identified in commander@2.20.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was commander checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan commander together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in commander@2.20.3, cost nothing.

Related security reports