Summary
Togoder Security scanned the npm package diff@4.0.2 on Oct 4, 2026. An AI review of 21 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Dynamic code transformation and registration
NPS-A1B74D13B997
The file uses @babel/register at the top level, which hooks into Node's module loading system and dynamically transpiles/executes JavaScript on the fly. While commonly used for development, it enables runtime code transformation and execution outside the package scope, which can be abused to alter or execute arbitrary code during import.
Import-time code execution
NPS-0A24483CACC5
Requiring runtime.js immediately triggers @babel/register's side effects, modifying global module loading behavior at import time. This is top-level execution and could serve as a vector for code tampering or hidden execution if the dependency or its configuration is compromised.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| runtime.js | medium | The file registers Babel's runtime transpiler at import time, which modifies module loading behavior and executes code dynamically, posing a moderate security risk if misused or compromised. |
| dist/diff.js | safe | No malicious patterns detected |
| lib/convert/dmp.js | safe | No malicious patterns detected |
| lib/convert/xml.js | safe | The code is a simple XML diff converter that escapes HTML characters and contains no malicious patterns. |
| lib/diff/array.js | safe | No malicious patterns detected; the file contains a straightforward array diff utility with no network, filesystem, process, or dynamic execution concerns. |
| lib/diff/base.js | safe | No malicious patterns detected; the code is a standard diff algorithm implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| lib/diff/character.js | safe | No malicious patterns detected |
| lib/diff/css.js | safe | No malicious patterns detected; the code is a standard CSS diff tokenizer with no network, filesystem, or code execution activity. |
| lib/diff/json.js | safe | No malicious patterns detected |
| lib/diff/line.js | safe | No malicious patterns detected; the file is a standard diff utility implementation with no network, filesystem, or process access. |
| lib/diff/sentence.js | safe | No malicious patterns detected; code performs a simple sentence-based diff operation with no network, filesystem, or execution activity. |
| lib/diff/word.js | safe | No malicious patterns detected |
| lib/index.es6.js | safe | No malicious patterns detected |
| lib/index.js | safe | This is a standard index file for the jsdiff library that only exports diff functions and contains no malicious patterns, network calls, file system access, or dynamic code execution. |
| lib/patch/apply.js | safe | No malicious patterns detected; the code is a standard unified diff patch application utility with no network, filesystem, process execution, or obfuscated payloads. |
| lib/patch/create.js | safe | No malicious patterns detected; the code is a standard diff/patch generation utility with no network, filesystem, or process execution activity. |
| lib/patch/merge.js | safe | No malicious patterns detected; the code is a standard patch merging utility with no network, filesystem, process, or dynamic execution risks. |
| lib/patch/parse.js | safe | No malicious patterns detected; the code is a straightforward unified diff parser with no network, filesystem, process, or dynamic execution activity. |
| lib/util/array.js | safe | No malicious patterns detected; the file contains only benign array comparison utility functions. |
| lib/util/distance-iterator.js | safe | No malicious patterns detected |
| lib/util/params.js | safe | No malicious patterns detected |
Affected version ranges
None of the 2 scanned versions of diff are flagged high or critical. The latest scanned version, 8.0.4, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 8.0.4 | No issues | 1 | 8.0.4 | |
| 4.0.4 โ 8.0.3 | Not scanned | 3 | >=4.0.4 <=8.0.3 | |
| 4.0.2 | Needs review | 1 | 4.0.2 | Dynamic code transformation and registration; Import-time code execution |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of diff
Frequently asked questions
Is diff safe to use?
No confirmed malware was found in diff@4.0.2, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.
Does diff contain malware?
No malware was identified in diff@4.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was diff checked?
Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan diff together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in diff@4.0.2, cost nothing.