Togoder security

npm package security report

es-iterator-helpers npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.4.0 Files reviewed 120 Size 92.4 KB Scanned

Summary

Togoder Security scanned the npm package es-iterator-helpers@1.4.0 on Oct 6, 2026. An AI review of 120 source files produced 69 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
69
medium
1
low

Findings 70

medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.concat/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.concat/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.concat/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.from/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.from/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.from/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.chunks/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.chunks/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.chunks/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.constructor/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.constructor/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.constructor/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.drop/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.drop/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.drop/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.every/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.every/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.every/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.filter/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.filter/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.filter/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.find/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.find/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.find/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.flatMap/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.flatMap/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.flatMap/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.forEach/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.forEach/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.forEach/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.includes/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.includes/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.includes/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.join/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.join/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.join/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.map/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.map/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.map/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.reduce/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.reduce/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.reduce/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.some/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.some/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.some/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.take/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.take/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.take/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.toArray/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.toArray/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.toArray/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype.windows/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype.windows/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype.windows/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.prototype/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.prototype/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.prototype/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.zip/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.zip/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.zip/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator.zipKeyed/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator.zipKeyed/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator.zipKeyed/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

Iterator/auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

Iterator/auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

Iterator/auto.js:3
medium

Indirect code execution via module import

NPS-2210B5D52705

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

auto.js:3
medium

Potential global environment modification

NPS-CE875577C6CA

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

auto.js:3
medium

Opaque dependency

NPS-03A39C1AC708

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

auto.js:3
low

Dynamic code execution / runtime dependency resolution

NPS-7239C77BA8E2

The module uses require('function-bind') and require('./polyfill') to resolve and load dependencies at runtime. While this is a common pattern for polyfills, the use of require with dynamic internal paths and the invocation of getPolyfill() could be exploited if the polyfill module is compromised. No direct evidence of malicious behavior, but the pattern warrants caution.

Iterator.prototype.constructor/index.js

Files reviewed

FileVerdictWhat the reviewer saw
Iterator.concat/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.from/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.chunks/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.constructor/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.constructor/index.js medium The code is a standard polyfill wrapper with no overt malicious patterns, but it relies on runtime module resolution which carries a low inherent risk.
Iterator.prototype.drop/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.every/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.filter/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.find/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.flatMap/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.forEach/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.includes/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.join/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.map/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.reduce/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.some/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.take/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.toArray/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype.windows/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.prototype/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.zip/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.zipKeyed/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator/auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
auto.js medium The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
Iterator.concat/implementation.js safe Cleared by Jev triage; no further analysis needed
Show 95 more files
FileVerdictWhat the reviewer saw
Iterator.concat/index.js safe No malicious patterns detected
Iterator.concat/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.concat/shim.js safe No malicious patterns detected
Iterator.from/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.from/index.js safe No malicious patterns detected
Iterator.from/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.from/shim.js safe No malicious patterns detected
Iterator.prototype.chunks/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.chunks/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.chunks/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.chunks/shim.js safe No malicious patterns detected
Iterator.prototype.constructor/implementation.js safe No malicious patterns detected; the file is a minimal polyfill wrapper that simply requires and re-exports the Iterator polyfill.
Iterator.prototype.constructor/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.constructor/shim.js safe No malicious patterns detected
Iterator.prototype.drop/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.drop/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.drop/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.drop/shim.js safe No malicious patterns detected; the code is a standard polyfill shim for Iterator.prototype.drop with no exfiltration, obfuscation, or suspicious behavior.
Iterator.prototype.every/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.every/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.every/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.every/shim.js safe No malicious patterns detected; the shim only polyfills Iterator.prototype.every using standard define-properties and local module references.
Iterator.prototype.filter/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.filter/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.filter/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.filter/shim.js safe No malicious patterns detected; the shim only standardizes Iterator.prototype.filter using define-properties and a local polyfill.
Iterator.prototype.find/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.find/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.find/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.find/shim.js safe No malicious patterns detected; the code is a standard polyfill shim for Iterator.prototype.find with no network, filesystem, process, or dynamic code execution behavior.
Iterator.prototype.flatMap/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.flatMap/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.flatMap/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.flatMap/shim.js safe No malicious patterns detected
Iterator.prototype.forEach/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.forEach/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.forEach/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.forEach/shim.js safe No malicious patterns detected
Iterator.prototype.includes/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.includes/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.includes/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.includes/shim.js safe No malicious patterns detected
Iterator.prototype.join/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.join/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.join/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.join/shim.js safe No malicious patterns detected
Iterator.prototype.map/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.map/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.map/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.map/shim.js safe No malicious patterns detected; the code is a legitimate polyfill shim for Iterator.prototype.map.
Iterator.prototype.reduce/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.reduce/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.reduce/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.reduce/shim.js safe This is a standard polyfill shim for Iterator.prototype.reduce that only performs prototype method installation with no malicious patterns detected.
Iterator.prototype.some/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.some/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.some/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.some/shim.js safe No malicious patterns detected
Iterator.prototype.take/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.take/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.take/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.take/shim.js safe No malicious patterns detected; the file only defines a standard polyfill shim for Iterator.prototype.take using local modules.
Iterator.prototype.toArray/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.toArray/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.toArray/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.toArray/shim.js safe No malicious patterns detected; the file is a standard polyfill shim that defines Iterator.prototype.toArray safely.
Iterator.prototype.windows/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.windows/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator.prototype.windows/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype.windows/shim.js safe No malicious patterns detected; this is a standard polyfill shim that safely installs Iterator.prototype.windows without any suspicious behavior.
Iterator.prototype/implementation.js safe No malicious patterns detected
Iterator.prototype/index.js safe No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype.
Iterator.prototype/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.prototype/shim.js safe No malicious patterns detected; this is a standard TC39 proposal polyfill shim for Iterator.prototype with no network, filesystem, process, or dynamic code execution activity.
Iterator.zip/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.zip/index.js safe No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype.
Iterator.zip/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.zip/shim.js safe No malicious patterns detected; the file is a standard iterator zip shim using local module requires and safe property definition.
Iterator.zipKeyed/implementation.js safe Cleared by Jev triage; no further analysis needed
Iterator.zipKeyed/index.js safe No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype.
Iterator.zipKeyed/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator.zipKeyed/shim.js safe No malicious patterns detected
Iterator/implementation.js safe This is a legitimate polyfill implementation for the Iterator constructor with no malicious patterns detected.
Iterator/index.js safe No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
Iterator/polyfill.js safe Cleared by Jev triage; no further analysis needed
Iterator/shim.js safe The file is a standard polyfill shim for the Iterator global, using only local requires and define-properties to install the polyfill; no malicious patterns detected.
IteratorHelperPrototype/index.js safe Cleared by Jev triage; no further analysis needed
WrapForValidIteratorPrototype/index.js safe Cleared by Jev triage; no further analysis needed
aos/GeneratorResumeAbrupt.js safe No malicious patterns detected
aos/GetOptionsObject.js safe Cleared by Jev triage; no further analysis needed
aos/IfAbruptCloseIterators.js safe Cleared by Jev triage; no further analysis needed
aos/IteratorCloseAll.js safe Cleared by Jev triage; no further analysis needed
aos/IteratorZip.js safe No malicious patterns detected; the code is a standard TC39 Iterator.zip proposal implementation using only well-known specification helper packages.
eslint.config.mjs safe Cleared by Jev triage; no further analysis needed
shim.js safe No malicious patterns detected; the file is a straightforward set of require calls and a shim function invoking Iterator helper polyfills.

Scanned versions of es-iterator-helpers

VersionVerdictFilesScanned
1.4.0 Needs review 120 Oct 6, 2026

Frequently asked questions

Is es-iterator-helpers safe to use?

No confirmed malware was found in es-iterator-helpers@1.4.0, but the review flagged 69 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does es-iterator-helpers contain malware?

No malware was identified in es-iterator-helpers@1.4.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was es-iterator-helpers checked?

Togoder Security downloaded the published npm package and had an AI model read its 120 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan es-iterator-helpers together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in es-iterator-helpers@1.4.0, cost nothing.

Related security reports