Summary
Togoder Security scanned the npm package cross-spawn@7.0.6 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Spawning processes
NPS-AF45F8FFDC33
The module directly uses child_process.spawn and child_process.spawnSync to execute commands. While this is the intended functionality of the cross-spawn package, it represents a capability that could be abused if the package is compromised. The command and arguments are derived from user input/arguments passed to the exported functions.
Spawning processes
NPS-56E21AFF070A
The module directly uses child_process.spawnSync to execute commands synchronously. This is consistent with the package's purpose but still represents a process execution capability.
Filesystem manipulation (process.chdir)
NPS-1CD7E3F777DD
The function temporarily changes the process working directory (process.chdir) to the user-supplied parsed.options.cwd before calling which.sync, then restores it. While this is intended to make which operate relative to a custom cwd, it is a global process-wide side effect that can affect other concurrent operations (e.g. other modules reading files by relative path) during that window, and relies on cwd being restorable. This is a legitimate technique used by cross-spawn but is a potential attack surface if parsed.options.cwd is attacker-controlled.
Path resolution based on unvalidated input
NPS-EC9D0BEB4D04
resolved is computed by which.sync using env[getPathKey({env})] as PATH and then path.resolve(hasCustomCwd ? parsed.options.cwd : '', resolved). If parsed.options or parsed.command are attacker-controlled, this can resolve to arbitrary paths outside the intended package scope. However, the function itself does not execute anything, it only resolves a path string.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | The code is the legitimate cross-spawn package implementation that wraps child_process to provide cross-platform compatibility; it spawns processes by design, with no evidence of exfiltration, obfuscation, or other malicious behavior. |
| lib/util/resolveCommand.js | medium | No malicious patterns detected; the code performs legitimate command path resolution with twp low-severity concerns around process-wide chdir and path resolution from caller-supplied cwd. |
| lib/enoent.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/parse.js | safe | This is a legitimate command parsing utility (similar to cross-spawn) that handles shell escaping and shebang detection without any malicious patterns. |
| lib/util/escape.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/util/readShebang.js | safe | No malicious patterns detected |
Scanned versions of cross-spawn
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 7.0.6 | Needs review | 6 | Oct 6, 2026 |
Frequently asked questions
Is cross-spawn safe to use?
No confirmed malware was found in cross-spawn@7.0.6, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does cross-spawn contain malware?
No malware was identified in cross-spawn@7.0.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was cross-spawn checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan cross-spawn together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in cross-spawn@7.0.6, cost nothing.