Togoder security

npm package security report

cosmiconfig@9.0.0 security report

Risky patterns found that deserve a look.

Needs review Version 9.0.0 Files reviewed 14 Size 42.4 KB Scanned

Summary

Togoder Security scanned the npm package cosmiconfig@9.0.0 on Oct 6, 2026. An AI review of 14 source files produced 2 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
4
low

Findings 6

medium

Dynamic Code Execution

NPS-8D184837CF3B

The module dynamically requires and executes code from external files using 'import-fresh', 'typescript', 'js-yaml', and 'parse-json'. While these are legitimate loaders for configuration files, the dynamic import and require mechanisms could be exploited if an attacker can control the input file paths or content, leading to arbitrary code execution. Additionally, the loader writes transpiled TypeScript to the filesystem and then imports it, which could be abused to execute malicious code if the input TypeScript is attacker-controlled.

dist/loaders.js
medium

File System Manipulation

NPS-387C308DF552

The loadTsSync and loadTs functions write compiled TypeScript files to the filesystem (compiledFilepath) and subsequently remove them. This could be abused to write files outside the intended directory if the filepath is user-controlled, potentially leading to unauthorized file writes or deletion. However, the file extensions are fixed (.cjs and .mjs) and the paths are derived from the input filepath.

dist/loaders.js
low

Cache manipulation

NPS-A788F33165CE

The code uses caching mechanisms (loadCache, searchCache) to store loaded configuration results. While not inherently malicious, caching could lead to stale or unintended data being served if the cache is not properly scoped or cleared.

dist/Explorer.js:28
low

File system traversal

NPS-D2C740B792EC

The search method traverses the filesystem upwards from a starting directory, checking for configuration files in parent directories and global locations. This is standard behavior for configuration loaders (like cosmiconfig) but could be used to discover sensitive files outside the intended package scope.

dist/Explorer.js:36
low

Dynamic file loading

NPS-2C23529332DD

The code supports $import directives in configuration files, allowing one config to load and merge other configuration files from the filesystem. While intended for legitimate config merging, this could be abused to read arbitrary files if an attacker can control config file contents, potentially leading to information disclosure if the loaded config data is later exposed or exfiltrated.

dist/Explorer.js:100
low

dynamic code execution

NPS-9F9EBB3E5493

The function uses new Function('id', 'return import(id);') solely to test whether the runtime supports dynamic import syntax. No user input is passed, no code is executed from external sources, and the constructed function is never invoked. This is a benign feature-detection pattern commonly used by Babel and similar tools.

dist/canUseDynamicImport.js:10

Files reviewed

FileVerdictWhat the reviewer saw
dist/Explorer.js medium The code appears to be a legitimate configuration file explorer with no obvious malicious patterns, but it includes dynamic file loading and filesystem traversal features that could be misused in certain scenarios.
dist/loaders.js medium The code is a legitimate set of loaders for configuration and TypeScript files, but it uses dynamic imports and filesystem writes that could pose a risk if input paths are untrusted; no direct malicious patterns were found.
dist/ExplorerBase.js safe No malicious patterns detected; this is a legitimate cosmiconfig-style configuration file explorer utility.
dist/ExplorerSync.js safe No malicious patterns detected; the code implements a configuration file explorer with file reading and import merging, but lacks any exfiltration, obfuscation, or process execution behavior.
dist/cacheWrapper.js safe No malicious patterns detected; the code is a simple cache wrapper utility with no network, filesystem, or process access.
dist/canUseDynamicImport.js safe The code is a benign feature-detection helper that uses new Function only to check for dynamic import support without executing external code or exhibiting any malicious behavior.
dist/defaults.js safe No malicious patterns detected; the file only defines configuration search paths and default loader mappings using standard loaders.
dist/getDirectory.js safe No malicious patterns detected; the code only uses path utilities and path-type to resolve directory paths without any network, filesystem, process, or dynamic execution activity.
dist/getPropertyByPath.js safe No malicious patterns detected
dist/index.js safe No malicious patterns detected; the file is a standard cosmiconfig library entry point that only uses relative requires and in-process configuration search logic.
dist/merge.js safe No malicious patterns detected; the code is a straightforward deep merge utility with no network, filesystem, process execution, or obfuscated behavior.
dist/readFile.js safe No malicious patterns detected; the file only provides standard file reading utilities using Node's fs module.
dist/types.js safe No malicious patterns detected
dist/util.js safe No malicious patterns detected

Frequently asked questions

Is cosmiconfig safe to use?

No confirmed malware was found in cosmiconfig@9.0.0, but the review flagged 2 medium, 4 low severity findings for risky patterns worth checking before you rely on it.

Does cosmiconfig contain malware?

No malware was identified in cosmiconfig@9.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was cosmiconfig checked?

Togoder Security downloaded the published npm package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan cosmiconfig together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in cosmiconfig@9.0.0, cost nothing.

Related security reports