Summary
Togoder Security scanned the npm package es-iterator-helpers@1.4.0 on Oct 6, 2026. An AI review of 120 source files produced 69 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 70
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Indirect code execution via module import
NPS-2210B5D52705
The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.
Potential global environment modification
NPS-CE875577C6CA
The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.
Opaque dependency
NPS-03A39C1AC708
The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.
Dynamic code execution / runtime dependency resolution
NPS-7239C77BA8E2
The module uses require('function-bind') and require('./polyfill') to resolve and load dependencies at runtime. While this is a common pattern for polyfills, the use of require with dynamic internal paths and the invocation of getPolyfill() could be exploited if the polyfill module is compromised. No direct evidence of malicious behavior, but the pattern warrants caution.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| Iterator.concat/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.from/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.chunks/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.constructor/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.constructor/index.js | medium | The code is a standard polyfill wrapper with no overt malicious patterns, but it relies on runtime module resolution which carries a low inherent risk. |
| Iterator.prototype.drop/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.every/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.filter/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.find/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.flatMap/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.forEach/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.includes/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.join/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.map/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.reduce/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.some/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.take/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.toArray/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype.windows/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.prototype/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.zip/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.zipKeyed/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator/auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| auto.js | medium | The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible. |
| Iterator.concat/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
Show 95 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| Iterator.concat/index.js | safe | No malicious patterns detected |
| Iterator.concat/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.concat/shim.js | safe | No malicious patterns detected |
| Iterator.from/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.from/index.js | safe | No malicious patterns detected |
| Iterator.from/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.from/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.chunks/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.chunks/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.chunks/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.chunks/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.constructor/implementation.js | safe | No malicious patterns detected; the file is a minimal polyfill wrapper that simply requires and re-exports the Iterator polyfill. |
| Iterator.prototype.constructor/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.constructor/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.drop/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.drop/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.drop/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.drop/shim.js | safe | No malicious patterns detected; the code is a standard polyfill shim for Iterator.prototype.drop with no exfiltration, obfuscation, or suspicious behavior. |
| Iterator.prototype.every/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.every/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.every/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.every/shim.js | safe | No malicious patterns detected; the shim only polyfills Iterator.prototype.every using standard define-properties and local module references. |
| Iterator.prototype.filter/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.filter/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.filter/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.filter/shim.js | safe | No malicious patterns detected; the shim only standardizes Iterator.prototype.filter using define-properties and a local polyfill. |
| Iterator.prototype.find/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.find/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.find/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.find/shim.js | safe | No malicious patterns detected; the code is a standard polyfill shim for Iterator.prototype.find with no network, filesystem, process, or dynamic code execution behavior. |
| Iterator.prototype.flatMap/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.flatMap/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.flatMap/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.flatMap/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.forEach/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.forEach/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.forEach/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.forEach/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.includes/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.includes/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.includes/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.includes/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.join/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.join/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.join/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.join/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.map/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.map/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.map/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.map/shim.js | safe | No malicious patterns detected; the code is a legitimate polyfill shim for Iterator.prototype.map. |
| Iterator.prototype.reduce/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.reduce/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.reduce/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.reduce/shim.js | safe | This is a standard polyfill shim for Iterator.prototype.reduce that only performs prototype method installation with no malicious patterns detected. |
| Iterator.prototype.some/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.some/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.some/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.some/shim.js | safe | No malicious patterns detected |
| Iterator.prototype.take/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.take/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.take/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.take/shim.js | safe | No malicious patterns detected; the file only defines a standard polyfill shim for Iterator.prototype.take using local modules. |
| Iterator.prototype.toArray/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.toArray/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.toArray/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.toArray/shim.js | safe | No malicious patterns detected; the file is a standard polyfill shim that defines Iterator.prototype.toArray safely. |
| Iterator.prototype.windows/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.windows/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator.prototype.windows/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype.windows/shim.js | safe | No malicious patterns detected; this is a standard polyfill shim that safely installs Iterator.prototype.windows without any suspicious behavior. |
| Iterator.prototype/implementation.js | safe | No malicious patterns detected |
| Iterator.prototype/index.js | safe | No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype. |
| Iterator.prototype/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.prototype/shim.js | safe | No malicious patterns detected; this is a standard TC39 proposal polyfill shim for Iterator.prototype with no network, filesystem, process, or dynamic code execution activity. |
| Iterator.zip/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.zip/index.js | safe | No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype. |
| Iterator.zip/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.zip/shim.js | safe | No malicious patterns detected; the file is a standard iterator zip shim using local module requires and safe property definition. |
| Iterator.zipKeyed/implementation.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.zipKeyed/index.js | safe | No malicious patterns detected; the file simply re-exports a polyfill for Iterator.prototype. |
| Iterator.zipKeyed/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator.zipKeyed/shim.js | safe | No malicious patterns detected |
| Iterator/implementation.js | safe | This is a legitimate polyfill implementation for the Iterator constructor with no malicious patterns detected. |
| Iterator/index.js | safe | No malicious patterns detected; the code is a standard polyfill wrapper using call-bind and a local polyfill module. |
| Iterator/polyfill.js | safe | Cleared by Jev triage; no further analysis needed |
| Iterator/shim.js | safe | The file is a standard polyfill shim for the Iterator global, using only local requires and define-properties to install the polyfill; no malicious patterns detected. |
| IteratorHelperPrototype/index.js | safe | Cleared by Jev triage; no further analysis needed |
| WrapForValidIteratorPrototype/index.js | safe | Cleared by Jev triage; no further analysis needed |
| aos/GeneratorResumeAbrupt.js | safe | No malicious patterns detected |
| aos/GetOptionsObject.js | safe | Cleared by Jev triage; no further analysis needed |
| aos/IfAbruptCloseIterators.js | safe | Cleared by Jev triage; no further analysis needed |
| aos/IteratorCloseAll.js | safe | Cleared by Jev triage; no further analysis needed |
| aos/IteratorZip.js | safe | No malicious patterns detected; the code is a standard TC39 Iterator.zip proposal implementation using only well-known specification helper packages. |
| eslint.config.mjs | safe | Cleared by Jev triage; no further analysis needed |
| shim.js | safe | No malicious patterns detected; the file is a straightforward set of require calls and a shim function invoking Iterator helper polyfills. |
Frequently asked questions
Is es-iterator-helpers safe to use?
No confirmed malware was found in es-iterator-helpers@1.4.0, but the review flagged 69 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does es-iterator-helpers contain malware?
No malware was identified in es-iterator-helpers@1.4.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was es-iterator-helpers checked?
Togoder Security downloaded the published npm package and had an AI model read its 120 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan es-iterator-helpers together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in es-iterator-helpers@1.4.0, cost nothing.