Togoder security

npm package security report

es-module-lexer npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.3.2 Files reviewed 7 Size 148.9 KB Scanned

Summary

Togoder Security scanned the npm package es-module-lexer@2.3.2 on Oct 6, 2026. An AI review of 7 source files produced 1 high, 7 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
7
medium
6
low

Findings 14

high

Dynamic code execution via eval

NPS-08A0E7A9994D

The code uses the global eval() function (input)" to interpret string slices from the parsed source. Although the result is caught and the same slicing is done on non-Buffer inputs, eval can lead to arbitrary code execution if the parsed content is attacker-controlled. This is a known pattern in some Babel/lexer minimal builds, but it is still a dangerous primitive.

dist/lexer.minimal.cjs
medium

Obfuscated/Encoded Payload

NPS-A215A04CB7F6

The file contains a large Base64-encoded WebAssembly module that is decoded and compiled at runtime (lines defining variable 'A' and function 'C'). This obfuscation prevents easy review of the WebAssembly functionality, which could contain hidden malicious code.

dist/lexer.cjs
medium

Dynamic Code Execution (eval)

NPS-78277B4F367C

The function 's' uses '(0,eval)(A)' to evaluate strings, which is a form of dynamic code execution. While the input is derived from parsed source code, this pattern can be exploited if the parser processes untrusted input.

dist/lexer.cjs
medium

WebAssembly Module Execution

NPS-9D6581B87702

The code compiles and instantiates a WebAssembly module from an encoded string, and subsequently calls many exported functions (e.g., E.parse, E.sa, etc.) to implement a lexer. WebAssembly can execute arbitrary low-level operations, and the encoded nature obscures its exact behavior.

dist/lexer.cjs
medium

Dynamic code execution (eval)

NPS-E646CE7422F1

The parser calls (0,eval)(A) on string slices from the input to unescape quoted strings. While this is a known pattern in es-module-lexer, using indirect eval on untrusted input is a dangerous construct that can execute arbitrary code if the input is attacker-controlled and the eval'd slice is not strictly a quoted string.

dist/lexer.js
medium

Embedded WebAssembly binary

NPS-FD2A346962F4

A large base64-encoded WebAssembly module is embedded and compiled/instantiated at runtime. This is a legitimate technique for distributing a fast lexer (likely SWC/Babel minimal), but hidden WASM can obscure malicious behavior and is a red flag when analyzing third-party packages.

dist/lexer.minimal.cjs
medium

Dynamic code execution (eval)

NPS-7DE2C2632FB7

The code uses the global eval() function inside the 'o' helper, which is called on slices of the scanned JavaScript source. This is part of es-module-lexer's design to evaluate import specifiers (e.g., string literals with escapes). However, eval() of arbitrary parsed source could theoretically execute side effects if the parser is fed malicious input and a bug causes it to evaluate non-literal code. This is a known pattern in es-module-lexer itself, but it is still a risky construct in a lexer.

dist/lexer.minimal.js
medium

Obfuscated embedded WebAssembly payload

NPS-67255767F8A0

A large base64-encoded WebAssembly binary is embedded in the file and decoded/compiled at load time via WebAssembly.compile/instantiate. While this is the standard es-module-lexer implementation (the WASM lexer core), an opaque binary payload that is instantiated at import time is a notable supply-chain risk: any modification of this blob could introduce arbitrary native-like behavior that is not human-auditable in this file. The code does not verify integrity (no hash/signature check) of the WASM payload before execution.

dist/lexer.minimal.js
low

Potential for Hidden Data Exfiltration

NPS-EF93903AFE8E

Although no explicit network requests are present in the JavaScript, the WebAssembly module could perform network operations or file system access if it imports such capabilities. The opaque nature of the module prevents verification.

dist/lexer.cjs
low

Encoded/embedded WebAssembly payload

NPS-E02B7B255D57

A large base64-encoded WebAssembly binary is embedded and compiled at import time via WebAssembly.compile/instantiate. This is the legitimate core lexer implementation of es-module-lexer, but the pattern (opaque binary blob loaded at import) is a common malware obfuscation vector and warrants review.

dist/lexer.js
low

Top-level execution at import time

NPS-5196853034E8

The module performs WebAssembly compilation at import time (init promise). This is expected behavior for this package, but import-time native code execution is a supply-chain risk category to note.

dist/lexer.js
low

Top-level asynchronous init on import

NPS-73790CE241B7

The module starts a WebAssembly compilation and instantiation immediately when imported (exports.init = WebAssembly.compile(E()).then(...)). This executes code at import time and is not gated by an explicit opt-in call.

dist/lexer.minimal.cjs
low

Obfuscated/minified code

NPS-94D13DDE0DC5

The file is minified and contains encoded strings (base64 WASM, obfuscated identifiers). While this is common for distributed builds, it reduces auditability and can hide behavior.

dist/lexer.minimal.cjs
low

Import-time code execution

NPS-08EC88B3804C

Top-level code decodes the base64 WASM blob and calls WebAssembly.compile(...).then(...), so nontrivial code (WASM instantiation) executes simply upon importing this module, before any exported function is called.

dist/lexer.minimal.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/lexer.cjs medium The file contains a heavily obfuscated WebAssembly payload and uses eval, which may hide malicious behavior, though no direct exfiltration or backdoor code is evident in the JavaScript layer.
dist/lexer.js medium This appears to be the legitimate es-module-lexer package using embedded WebAssembly and a limited eval-based string unescape, but the eval on input-derived strings and embedded opaque WASM blob are noteworthy risk indicators rather than confirmed malicious behavior.
dist/lexer.minimal.cjs medium This appears to be a legitimate minimal lexer/parser (likely from Babel/SWC) but contains risky patterns such as eval() on parsed source and an embedded WebAssembly module, warranting a warning rather than a safe classification.
dist/lexer.minimal.js medium This appears to be the legitimate es-module-lexer package (v2.3.2) with its standard embedded WASM lexer and a localized eval() used to decode import specifiers; no exfiltration, credential harvesting, process spawning, or network access is present, but the embedded opaque WASM blob and eval usage warrant caution and version/integrity verification.
dist/lexer.asm.js safe No malicious patterns detected; this is a legitimate WebAssembly-based JavaScript lexer (es-module-lexer) with no network, filesystem, process, or credential access.
dist/lexer.minimal.asm.js safe This is the official es-module-lexer WebAssembly-based JavaScript lexer package (version 2.3.2); no malicious patterns, exfiltration, credential harvesting, or dynamic code execution were detected.
lexer.js safe No malicious patterns detected

Scanned versions of es-module-lexer

VersionVerdictFilesScanned
2.3.2 Needs review 7 Oct 6, 2026

Frequently asked questions

Is es-module-lexer safe to use?

No confirmed malware was found in es-module-lexer@2.3.2, but the review flagged 1 high, 7 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does es-module-lexer contain malware?

No malware was identified in es-module-lexer@2.3.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was es-module-lexer checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan es-module-lexer together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in es-module-lexer@2.3.2, cost nothing.

Related security reports