# es-iterator-helpers@1.4.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:09.000Z
- Files reviewed: 120
- Findings: 69 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/es-iterator-helpers
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package es-iterator-helpers@1.4.0 on Oct 6, 2026. An AI review of 120 source files produced 69 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.concat/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.concat/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.concat/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.from/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.from/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.from/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.chunks/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.chunks/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.chunks/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.constructor/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.constructor/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.constructor/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.drop/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.drop/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.drop/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.every/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.every/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.every/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.filter/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.filter/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.filter/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.find/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.find/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.find/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.flatMap/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.flatMap/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.flatMap/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.forEach/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.forEach/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.forEach/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.includes/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.includes/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.includes/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.join/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.join/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.join/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.map/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.map/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.map/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.reduce/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.reduce/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.reduce/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.some/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.some/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.some/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.take/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.take/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.take/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.toArray/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.toArray/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.toArray/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype.windows/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype.windows/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype.windows/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.prototype/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.prototype/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.prototype/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.zip/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.zip/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.zip/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator.zipKeyed/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator.zipKeyed/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator.zipKeyed/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `Iterator/auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `Iterator/auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `Iterator/auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [medium] Indirect code execution via module import

Finding ID: `NPS-2210B5D52705`

File: `auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-CE875577C6CA`

File: `auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-03A39C1AC708`

File: `auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [low] Dynamic code execution / runtime dependency resolution

Finding ID: `NPS-7239C77BA8E2`

File: `Iterator.prototype.constructor/index.js`

The module uses require('function-bind') and require('./polyfill') to resolve and load dependencies at runtime. While this is a common pattern for polyfills, the use of require with dynamic internal paths and the invocation of getPolyfill() could be exploited if the polyfill module is compromised. No direct evidence of malicious behavior, but the pattern warrants caution.

## Files reviewed

- `Iterator.concat/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.from/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.chunks/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.constructor/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.constructor/index.js` (medium): The code is a standard polyfill wrapper with no overt malicious patterns, but it relies on runtime module resolution which carries a low inherent risk.
- `Iterator.prototype.drop/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.every/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.filter/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.find/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.flatMap/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.forEach/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.includes/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.join/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.map/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.reduce/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.some/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.take/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.toArray/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype.windows/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.prototype/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.zip/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.zipKeyed/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator/auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `Iterator.concat/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.concat/index.js` (safe): No malicious patterns detected
- `Iterator.concat/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.concat/shim.js` (safe): No malicious patterns detected
- `Iterator.from/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.from/index.js` (safe): No malicious patterns detected
- `Iterator.from/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.from/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.chunks/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.chunks/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.chunks/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.chunks/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.constructor/implementation.js` (safe): No malicious patterns detected; the file is a minimal polyfill wrapper that simply requires and re-exports the Iterator polyfill.
- `Iterator.prototype.constructor/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.constructor/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.drop/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.drop/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.drop/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.drop/shim.js` (safe): No malicious patterns detected; the code is a standard polyfill shim for Iterator.prototype.drop with no exfiltration, obfuscation, or suspicious behavior.
- `Iterator.prototype.every/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.every/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.every/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.every/shim.js` (safe): No malicious patterns detected; the shim only polyfills Iterator.prototype.every using standard define-properties and local module references.
- `Iterator.prototype.filter/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.filter/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.filter/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.filter/shim.js` (safe): No malicious patterns detected; the shim only standardizes Iterator.prototype.filter using define-properties and a local polyfill.
- `Iterator.prototype.find/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.find/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.find/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.find/shim.js` (safe): No malicious patterns detected; the code is a standard polyfill shim for Iterator.prototype.find with no network, filesystem, process, or dynamic code execution behavior.
- `Iterator.prototype.flatMap/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.flatMap/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.flatMap/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.flatMap/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.forEach/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.forEach/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.forEach/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.forEach/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.includes/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.includes/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.includes/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.includes/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.join/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.join/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.join/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.join/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.map/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.map/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.map/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.map/shim.js` (safe): No malicious patterns detected; the code is a legitimate polyfill shim for Iterator.prototype.map.
- `Iterator.prototype.reduce/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.reduce/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.reduce/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.reduce/shim.js` (safe): This is a standard polyfill shim for Iterator.prototype.reduce that only performs prototype method installation with no malicious patterns detected.
- `Iterator.prototype.some/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.some/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.some/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.some/shim.js` (safe): No malicious patterns detected
- `Iterator.prototype.take/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.take/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.take/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.take/shim.js` (safe): No malicious patterns detected; the file only defines a standard polyfill shim for Iterator.prototype.take using local modules.
- `Iterator.prototype.toArray/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.toArray/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.toArray/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.toArray/shim.js` (safe): No malicious patterns detected; the file is a standard polyfill shim that defines Iterator.prototype.toArray safely.
- `Iterator.prototype.windows/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.windows/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator.prototype.windows/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype.windows/shim.js` (safe): No malicious patterns detected; this is a standard polyfill shim that safely installs Iterator.prototype.windows without any suspicious behavior.
- `Iterator.prototype/implementation.js` (safe): No malicious patterns detected
- `Iterator.prototype/index.js` (safe): No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype.
- `Iterator.prototype/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.prototype/shim.js` (safe): No malicious patterns detected; this is a standard TC39 proposal polyfill shim for Iterator.prototype with no network, filesystem, process, or dynamic code execution activity.
- `Iterator.zip/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.zip/index.js` (safe): No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype.
- `Iterator.zip/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.zip/shim.js` (safe): No malicious patterns detected; the file is a standard iterator zip shim using local module requires and safe property definition.
- `Iterator.zipKeyed/implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.zipKeyed/index.js` (safe): No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype.
- `Iterator.zipKeyed/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator.zipKeyed/shim.js` (safe): No malicious patterns detected
- `Iterator/implementation.js` (safe): This is a legitimate polyfill implementation for the Iterator constructor with no malicious patterns detected.
- `Iterator/index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module.
- `Iterator/polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `Iterator/shim.js` (safe): The file is a standard polyfill shim for the Iterator global, using only local requires and define-properties to install the polyfill; no malicious patterns detected.
- `IteratorHelperPrototype/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `WrapForValidIteratorPrototype/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `aos/GeneratorResumeAbrupt.js` (safe): No malicious patterns detected
- `aos/GetOptionsObject.js` (safe): Cleared by Jev triage; no further analysis needed
- `aos/IfAbruptCloseIterators.js` (safe): Cleared by Jev triage; no further analysis needed
- `aos/IteratorCloseAll.js` (safe): Cleared by Jev triage; no further analysis needed
- `aos/IteratorZip.js` (safe): No malicious patterns detected; the code is a standard TC39 Iterator.zip proposal implementation using only well-known specification helper packages.
- `eslint.config.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `shim.js` (safe): No malicious patterns detected; the file is a straightforward set of require calls and a shim function invoking Iterator helper polyfills.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
