Togoder security

npm package security report

engine.io-client npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 6.6.3 Files reviewed 55 Size 291.7 KB Scanned

Summary

Togoder Security scanned the npm package engine.io-client@6.6.3 on Oct 4, 2026. An AI review of 55 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
6
low

Findings 7

medium

dynamic code execution

NPS-44D2A017A41A

The globalThisShim uses Function('return this')() to obtain the global object when self and window are undefined. While this is a common JavaScript polyfill pattern, it relies on dynamic function construction, which can be problematic in environments with strict Content Security Policy (CSP) and is sometimes used to obscure execution context. It is not an outright malicious payload, but it is a notable red flag.

build/cjs/globals.js:18
low

empty function definition

NPS-A961CA268C62

createCookieJar is declared but contains no implementation. This is not inherently malicious, but could indicate incomplete or placeholder code. It is not a security concern on its own.

build/cjs/globals.js:23
low

Dynamic code execution

NPS-343454B9FA50

Uses Function("return this")() to evaluate code dynamically. While this is a common pattern to obtain the global object in environments without 'self' or 'window' (e.g., some JavaScript engines), it is a potential red flag because dynamic code execution via Function constructor can be used for obfuscation or exploitation if the input were ever variable or tainted. Here the string is hardcoded and benign, but it is worth noting as a pattern that can mask malicious intent in other contexts.

build/esm-debug/globals.js:16
low

Empty function definition

NPS-BDF825038780

The createCookieJar function is defined but empty, which is unusual. In some packages, stub implementations can be placeholders for functionality that is later replaced or monkey-patched. However, in this isolated file there is no evidence of malicious behavior; it is likely an incomplete or intentionally empty utility.

build/esm-debug/globals.js:21
low

No malicious patterns

NPS-2B6DC317B591

The code is part of the engine.io-client library and implements XHR polling transport for Socket.IO. It uses standard XMLHttpRequest APIs, has no dynamic code execution (no eval/new Function), no child_process/shell usage, no file system access outside browser context, no credential/secret harvesting, no cryptocurrency mining or wallet draining, and no data exfiltration to unexpected endpoints. Network requests target the configured Socket.IO server URI as expected for the library's purpose.

build/esm-debug/transports/polling-xhr.js
low

Dynamic code execution

NPS-343454B9FA50

Uses Function("return this")() to evaluate code dynamically. While this is a common pattern to obtain the global object in environments without 'self' or 'window' (e.g., some JavaScript engines), it is a potential red flag because dynamic code execution via Function constructor can be used for obfuscation or exploitation if the input were ever variable or tainted. Here the string is hardcoded and benign, but it is worth noting as a pattern that can mask malicious intent in other contexts.

build/esm/globals.js:16
low

Empty function definition

NPS-BDF825038780

The createCookieJar function is defined but empty, which is unusual. In some packages, stub implementations can be placeholders for functionality that is later replaced or monkey-patched. However, in this isolated file there is no evidence of malicious behavior; it is likely an incomplete or intentionally empty utility.

build/esm/globals.js:21

Files reviewed

FileVerdictWhat the reviewer saw
build/cjs/globals.js medium This file contains a dynamic Function constructor for global object shimming, which is a mild security concern, but no data exfiltration, credential harvesting, or network/process activity was found.
build/esm-debug/globals.js medium The code uses the Function constructor for global object detection and contains an empty cookie jar stub, but no clear malicious patterns such as data exfiltration, credential harvesting, or backdoor installation were found.
build/esm/globals.js medium The code uses the Function constructor for global object detection and contains an empty cookie jar stub, but no clear malicious patterns such as data exfiltration, credential harvesting, or backdoor installation were found.
build/cjs/browser-entrypoint.js safe No malicious patterns detected
build/cjs/contrib/has-cors.js safe No malicious patterns detected; the code only performs a feature-detection check for XMLHttpRequest CORS support.
build/cjs/contrib/parseqs.js safe Cleared by Jev triage; no further analysis needed
build/cjs/contrib/parseuri.js safe The code is a legitimate URI parser with no malicious patterns, network calls, credential harvesting, or dynamic execution.
build/cjs/globals.node.js safe No malicious patterns detected; the code is a standard cookie parsing and jar implementation for Node.js HTTP clients.
build/cjs/index.js safe No malicious patterns detected; this is a standard barrel file re-exporting socket.io-client modules.
build/cjs/socket.js safe This is the legitimate engine.io-client Socket implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, backdoors, or suspicious process/network activity.
build/cjs/transport.js safe No malicious patterns detected in the provided Transport base class implementation from engine.io-client.
build/cjs/transports/index.js safe No malicious patterns detected
build/cjs/transports/polling-fetch.js safe No malicious patterns detected; the code implements a standard fetch-based HTTP long-polling transport with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/cjs/transports/polling-xhr.js safe This is the standard engine.io-client XHR polling transport implementation with no malicious patterns detected.
build/cjs/transports/polling-xhr.node.js safe No malicious patterns detected; the code is a standard TypeScript-compiled CommonJS module implementing XMLHttpRequest-based polling transport for Socket.IO.
build/cjs/transports/polling.js safe This file is a standard engine.io-client polling transport implementation with no malicious patterns, obfuscation, data exfiltration, or suspicious behavior detected.
build/cjs/transports/websocket.js safe This file is a legitimate engine.io-client WebSocket transport implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution.
build/cjs/transports/websocket.node.js safe No malicious patterns detected; the file is a standard WebSocket transport implementation using the 'ws' package with expected cookie handling and compression logic.
build/cjs/transports/webtransport.js safe This is a legitimate WebTransport transport implementation for engine.io-client with no malicious patterns detected.
build/cjs/util.js safe No malicious patterns detected; the code contains only benign utility functions for object picking, timer installation, byte length calculation, and random string generation.
build/esm-debug/browser-entrypoint.js safe No malicious patterns detected
build/esm-debug/contrib/has-cors.js safe No malicious patterns detected; the code is a straightforward feature-detection snippet for CORS support in browsers.
build/esm-debug/contrib/parseqs.js safe Cleared by Jev triage; no further analysis needed
build/esm-debug/contrib/parseuri.js safe No malicious patterns detected; the code is a standard URI parser with no network, filesystem, process execution, or obfuscation concerns.
build/esm-debug/globals.node.js safe No malicious patterns detected; the code implements a standard Node.js cookie jar utility with no network, filesystem, or process manipulation beyond normal HTTP header handling.
Show 30 more files
FileVerdictWhat the reviewer saw
build/esm-debug/index.js safe No malicious patterns detected; file only contains standard re-exports for the socket.io-client package.
build/esm-debug/socket.js safe This is the legitimate engine.io-client socket implementation; no malicious patterns such as exfiltration, eval, credential harvesting, or process spawning were detected.
build/esm-debug/transport.js safe No malicious patterns detected in the transport.js file; it is a legitimate part of the engine.io-client library with standard networking and error handling code.
build/esm-debug/transports/index.js safe No malicious patterns detected; the file only imports transport implementations and exports a mapping with no executable or suspicious behavior.
build/esm-debug/transports/polling-fetch.js safe No malicious patterns detected; the file implements standard HTTP long-polling using fetch with cookie handling and no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
build/esm-debug/transports/polling-xhr.js safe No malicious patterns detected; this is legitimate engine.io-client XHR polling transport code.
build/esm-debug/transports/polling-xhr.node.js safe No malicious patterns detected; the code is a legitimate XMLHttpRequest-based transport implementation for Socket.IO client using the xmlhttprequest-ssl package.
build/esm-debug/transports/polling.js safe This file is a legitimate part of the engine.io-client polling transport implementation and contains no malicious patterns.
build/esm-debug/transports/websocket.js safe No malicious patterns detected; the code is a standard engine.io WebSocket transport implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/esm-debug/transports/websocket.node.js safe No malicious patterns detected; the code is a standard WebSocket transport implementation that delegates to the ws library without exfiltration, dynamic execution, or suspicious behavior.
build/esm-debug/transports/webtransport.js safe No malicious patterns detected; the code is a standard WebTransport transport implementation for engine.io-client without any exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/esm-debug/util.js safe Cleared by Jev triage; no further analysis needed
build/esm/browser-entrypoint.js safe No malicious patterns detected
build/esm/contrib/has-cors.js safe No malicious patterns detected; the code is a straightforward feature-detection snippet for CORS support in browsers.
build/esm/contrib/parseqs.js safe Cleared by Jev triage; no further analysis needed
build/esm/contrib/parseuri.js safe No malicious patterns detected; the code is a standard URI parser with no network, filesystem, process execution, or obfuscation concerns.
build/esm/globals.node.js safe No malicious patterns detected; the code implements a standard Node.js cookie jar utility with no network, filesystem, or process manipulation beyond normal HTTP header handling.
build/esm/index.js safe No malicious patterns detected; file only contains standard re-exports for the socket.io-client package.
build/esm/socket.js safe No malicious patterns detected; this is the legitimate engine.io-client Socket implementation with standard networking, event handling, and timer logic.
build/esm/transport.js safe No malicious patterns detected
build/esm/transports/index.js safe No malicious patterns detected; the file only imports transport implementations and exports a mapping with no executable or suspicious behavior.
build/esm/transports/polling-fetch.js safe No malicious patterns detected; the file implements standard HTTP long-polling using fetch with cookie handling and no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
build/esm/transports/polling-xhr.js safe No malicious patterns detected; this is a legitimate Socket.IO XHR polling transport implementation.
build/esm/transports/polling-xhr.node.js safe No malicious patterns detected; the code is a legitimate XMLHttpRequest-based transport implementation for Socket.IO client using the xmlhttprequest-ssl package.
build/esm/transports/polling.js safe No malicious patterns detected; this is a standard engine.io WebSocket polling transport implementation with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network activity.
build/esm/transports/websocket.js safe The code is a standard engine.io WebSocket transport implementation with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file system operations.
build/esm/transports/websocket.node.js safe No malicious patterns detected; the code is a standard WebSocket transport implementation that delegates to the ws library without exfiltration, dynamic execution, or suspicious behavior.
build/esm/transports/webtransport.js safe No malicious patterns detected; the code implements a standard WebTransport client transport using the engine.io-parser library without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
build/esm/util.js safe Cleared by Jev triage; no further analysis needed
dist/engine.io.js safe No malicious patterns detected; the code is the standard Engine.IO client library with only legitimate networking and utility functions.

Scanned versions of engine.io-client

VersionVerdictFilesScanned
6.6.3 Needs review 55 Oct 4, 2026

Frequently asked questions

Is engine.io-client safe to use?

No confirmed malware was found in engine.io-client@6.6.3, but the review flagged 1 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does engine.io-client contain malware?

No malware was identified in engine.io-client@6.6.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was engine.io-client checked?

Togoder Security downloaded the published npm package and had an AI model read its 55 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan engine.io-client together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in engine.io-client@6.6.3, cost nothing.

Related security reports