Togoder security

npm package security report

diff@4.0.2 security report

Risky patterns found that deserve a look.

Needs review Version 4.0.2 Files reviewed 21 Size 281.0 KB Scanned

Summary

Togoder Security scanned the npm package diff@4.0.2 on Oct 4, 2026. An AI review of 21 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
0
low

Findings 2

medium

Dynamic code transformation and registration

NPS-A1B74D13B997

The file uses @babel/register at the top level, which hooks into Node's module loading system and dynamically transpiles/executes JavaScript on the fly. While commonly used for development, it enables runtime code transformation and execution outside the package scope, which can be abused to alter or execute arbitrary code during import.

runtime.js:1
medium

Import-time code execution

NPS-0A24483CACC5

Requiring runtime.js immediately triggers @babel/register's side effects, modifying global module loading behavior at import time. This is top-level execution and could serve as a vector for code tampering or hidden execution if the dependency or its configuration is compromised.

runtime.js:1

Files reviewed

FileVerdictWhat the reviewer saw
runtime.js medium The file registers Babel's runtime transpiler at import time, which modifies module loading behavior and executes code dynamically, posing a moderate security risk if misused or compromised.
dist/diff.js safe No malicious patterns detected
lib/convert/dmp.js safe No malicious patterns detected
lib/convert/xml.js safe The code is a simple XML diff converter that escapes HTML characters and contains no malicious patterns.
lib/diff/array.js safe No malicious patterns detected; the file contains a straightforward array diff utility with no network, filesystem, process, or dynamic execution concerns.
lib/diff/base.js safe No malicious patterns detected; the code is a standard diff algorithm implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
lib/diff/character.js safe No malicious patterns detected
lib/diff/css.js safe No malicious patterns detected; the code is a standard CSS diff tokenizer with no network, filesystem, or code execution activity.
lib/diff/json.js safe No malicious patterns detected
lib/diff/line.js safe No malicious patterns detected; the file is a standard diff utility implementation with no network, filesystem, or process access.
lib/diff/sentence.js safe No malicious patterns detected; code performs a simple sentence-based diff operation with no network, filesystem, or execution activity.
lib/diff/word.js safe No malicious patterns detected
lib/index.es6.js safe No malicious patterns detected
lib/index.js safe This is a standard index file for the jsdiff library that only exports diff functions and contains no malicious patterns, network calls, file system access, or dynamic code execution.
lib/patch/apply.js safe No malicious patterns detected; the code is a standard unified diff patch application utility with no network, filesystem, process execution, or obfuscated payloads.
lib/patch/create.js safe No malicious patterns detected; the code is a standard diff/patch generation utility with no network, filesystem, or process execution activity.
lib/patch/merge.js safe No malicious patterns detected; the code is a standard patch merging utility with no network, filesystem, process, or dynamic execution risks.
lib/patch/parse.js safe No malicious patterns detected; the code is a straightforward unified diff parser with no network, filesystem, process, or dynamic execution activity.
lib/util/array.js safe No malicious patterns detected; the file contains only benign array comparison utility functions.
lib/util/distance-iterator.js safe No malicious patterns detected
lib/util/params.js safe No malicious patterns detected

Affected version ranges

None of the 2 scanned versions of diff are flagged high or critical. The latest scanned version, 8.0.4, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

4.0.28.0.4
VersionsVerdictCountRangeTop findings
8.0.4 No issues 1 8.0.4
4.0.4 โ€“ 8.0.3 Not scanned 3 >=4.0.4 <=8.0.3
4.0.2 Needs review 1 4.0.2 Dynamic code transformation and registration; Import-time code execution

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of diff

VersionVerdictFilesScanned
8.0.4 No issues 44 Oct 6, 2026
4.0.2 Needs review 21 Oct 4, 2026

Frequently asked questions

Is diff safe to use?

No confirmed malware was found in diff@4.0.2, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.

Does diff contain malware?

No malware was identified in diff@4.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was diff checked?

Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan diff together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in diff@4.0.2, cost nothing.

Related security reports