Togoder security

npm package security report

cross-spawn npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 7.0.6 Files reviewed 6 Size 9.0 KB Scanned

Summary

Togoder Security scanned the npm package cross-spawn@7.0.6 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
2
low

Findings 4

medium

Spawning processes

NPS-AF45F8FFDC33

The module directly uses child_process.spawn and child_process.spawnSync to execute commands. While this is the intended functionality of the cross-spawn package, it represents a capability that could be abused if the package is compromised. The command and arguments are derived from user input/arguments passed to the exported functions.

index.js:11
medium

Spawning processes

NPS-56E21AFF070A

The module directly uses child_process.spawnSync to execute commands synchronously. This is consistent with the package's purpose but still represents a process execution capability.

index.js:25
low

Filesystem manipulation (process.chdir)

NPS-1CD7E3F777DD

The function temporarily changes the process working directory (process.chdir) to the user-supplied parsed.options.cwd before calling which.sync, then restores it. While this is intended to make which operate relative to a custom cwd, it is a global process-wide side effect that can affect other concurrent operations (e.g. other modules reading files by relative path) during that window, and relies on cwd being restorable. This is a legitimate technique used by cross-spawn but is a potential attack surface if parsed.options.cwd is attacker-controlled.

lib/util/resolveCommand.js:15
low

Path resolution based on unvalidated input

NPS-EC9D0BEB4D04

resolved is computed by which.sync using env[getPathKey({env})] as PATH and then path.resolve(hasCustomCwd ? parsed.options.cwd : '', resolved). If parsed.options or parsed.command are attacker-controlled, this can resolve to arbitrary paths outside the intended package scope. However, the function itself does not execute anything, it only resolves a path string.

lib/util/resolveCommand.js:26

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The code is the legitimate cross-spawn package implementation that wraps child_process to provide cross-platform compatibility; it spawns processes by design, with no evidence of exfiltration, obfuscation, or other malicious behavior.
lib/util/resolveCommand.js medium No malicious patterns detected; the code performs legitimate command path resolution with twp low-severity concerns around process-wide chdir and path resolution from caller-supplied cwd.
lib/enoent.js safe Cleared by Jev triage; no further analysis needed
lib/parse.js safe This is a legitimate command parsing utility (similar to cross-spawn) that handles shell escaping and shebang detection without any malicious patterns.
lib/util/escape.js safe Cleared by Jev triage; no further analysis needed
lib/util/readShebang.js safe No malicious patterns detected

Scanned versions of cross-spawn

VersionVerdictFilesScanned
7.0.6 Needs review 6 Oct 6, 2026

Frequently asked questions

Is cross-spawn safe to use?

No confirmed malware was found in cross-spawn@7.0.6, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does cross-spawn contain malware?

No malware was identified in cross-spawn@7.0.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was cross-spawn checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan cross-spawn together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in cross-spawn@7.0.6, cost nothing.

Related security reports