Summary
Togoder Security scanned the npm package depd@2.0.0 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic code execution
NPS-C9542C6FF311
The wrapfunction function uses new Function() to dynamically construct a wrapper function from string concatenation. While this is a legitimate pattern in the depd library for preserving function arity, dynamic code generation of this nature can be a vector for code injection if the input is untrusted. In this specific implementation, all interpolated values (args, which is derived from fn.length) are controlled and numeric, so the risk is low in context, but the pattern warrants flagging.
File system path exposure
NPS-38FA718D12FC
basePath = process.cwd() is captured at module load time and used with path.relative to format stack locations for deprecation warnings written to stderr. This is standard diagnostic behavior and does not exfiltrate or manipulate files.
Environment variable access
NPS-43456D4B8993
The isignored and istraced functions read process.env.NO_DEPRECATION and process.env.TRACE_DEPRECATION, and check process.noDeprecation and process.traceDeprecation. These are standard Node.js deprecation control variables used for legitimate configuration, not credential harvesting.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | This is the well-known depd deprecation-warning utility; it uses new Function for arity-preserving wrappers (a common benign pattern) and reads standard deprecation env vars, with no evidence of exfiltration, credential theft, backdoors, or process spawning. |
| lib/browser/index.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of depd
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.0.0 | Needs review | 2 | Oct 4, 2026 |
Frequently asked questions
Is depd safe to use?
No confirmed malware was found in depd@2.0.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does depd contain malware?
No malware was identified in depd@2.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was depd checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan depd together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in depd@2.0.0, cost nothing.