# es-module-lexer@2.3.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:12.000Z
- Files reviewed: 7
- Findings: 1 high, 7 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/es-module-lexer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package es-module-lexer@2.3.2 on Oct 6, 2026. An AI review of 7 source files produced 1 high, 7 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Dynamic code execution via eval

Finding ID: `NPS-08A0E7A9994D`

File: `dist/lexer.minimal.cjs`

The code uses the global eval() function (input)" to interpret string slices from the parsed source. Although the result is caught and the same slicing is done on non-Buffer inputs, eval can lead to arbitrary code execution if the parsed content is attacker-controlled. This is a known pattern in some Babel/lexer minimal builds, but it is still a dangerous primitive.

### [medium] Obfuscated/Encoded Payload

Finding ID: `NPS-A215A04CB7F6`

File: `dist/lexer.cjs`

The file contains a large Base64-encoded WebAssembly module that is decoded and compiled at runtime (lines defining variable 'A' and function 'C'). This obfuscation prevents easy review of the WebAssembly functionality, which could contain hidden malicious code.

### [medium] Dynamic Code Execution (eval)

Finding ID: `NPS-78277B4F367C`

File: `dist/lexer.cjs`

The function 's' uses '(0,eval)(A)' to evaluate strings, which is a form of dynamic code execution. While the input is derived from parsed source code, this pattern can be exploited if the parser processes untrusted input.

### [medium] WebAssembly Module Execution

Finding ID: `NPS-9D6581B87702`

File: `dist/lexer.cjs`

The code compiles and instantiates a WebAssembly module from an encoded string, and subsequently calls many exported functions (e.g., E.parse, E.sa, etc.) to implement a lexer. WebAssembly can execute arbitrary low-level operations, and the encoded nature obscures its exact behavior.

### [medium] Dynamic code execution (eval)

Finding ID: `NPS-E646CE7422F1`

File: `dist/lexer.js`

The parser calls (0,eval)(A) on string slices from the input to unescape quoted strings. While this is a known pattern in es-module-lexer, using indirect eval on untrusted input is a dangerous construct that can execute arbitrary code if the input is attacker-controlled and the eval'd slice is not strictly a quoted string.

### [medium] Embedded WebAssembly binary

Finding ID: `NPS-FD2A346962F4`

File: `dist/lexer.minimal.cjs`

A large base64-encoded WebAssembly module is embedded and compiled/instantiated at runtime. This is a legitimate technique for distributing a fast lexer (likely SWC/Babel minimal), but hidden WASM can obscure malicious behavior and is a red flag when analyzing third-party packages.

### [medium] Dynamic code execution (eval)

Finding ID: `NPS-7DE2C2632FB7`

File: `dist/lexer.minimal.js`

The code uses the global eval() function inside the 'o' helper, which is called on slices of the scanned JavaScript source. This is part of es-module-lexer's design to evaluate import specifiers (e.g., string literals with escapes). However, eval() of arbitrary parsed source could theoretically execute side effects if the parser is fed malicious input and a bug causes it to evaluate non-literal code. This is a known pattern in es-module-lexer itself, but it is still a risky construct in a lexer.

### [medium] Obfuscated embedded WebAssembly payload

Finding ID: `NPS-67255767F8A0`

File: `dist/lexer.minimal.js`

A large base64-encoded WebAssembly binary is embedded in the file and decoded/compiled at load time via WebAssembly.compile/instantiate. While this is the standard es-module-lexer implementation (the WASM lexer core), an opaque binary payload that is instantiated at import time is a notable supply-chain risk: any modification of this blob could introduce arbitrary native-like behavior that is not human-auditable in this file. The code does not verify integrity (no hash/signature check) of the WASM payload before execution.

### [low] Potential for Hidden Data Exfiltration

Finding ID: `NPS-EF93903AFE8E`

File: `dist/lexer.cjs`

Although no explicit network requests are present in the JavaScript, the WebAssembly module could perform network operations or file system access if it imports such capabilities. The opaque nature of the module prevents verification.

### [low] Encoded/embedded WebAssembly payload

Finding ID: `NPS-E02B7B255D57`

File: `dist/lexer.js`

A large base64-encoded WebAssembly binary is embedded and compiled at import time via WebAssembly.compile/instantiate. This is the legitimate core lexer implementation of es-module-lexer, but the pattern (opaque binary blob loaded at import) is a common malware obfuscation vector and warrants review.

### [low] Top-level execution at import time

Finding ID: `NPS-5196853034E8`

File: `dist/lexer.js`

The module performs WebAssembly compilation at import time (init promise). This is expected behavior for this package, but import-time native code execution is a supply-chain risk category to note.

### [low] Top-level asynchronous init on import

Finding ID: `NPS-73790CE241B7`

File: `dist/lexer.minimal.cjs`

The module starts a WebAssembly compilation and instantiation immediately when imported (exports.init = WebAssembly.compile(E()).then(...)). This executes code at import time and is not gated by an explicit opt-in call.

### [low] Obfuscated/minified code

Finding ID: `NPS-94D13DDE0DC5`

File: `dist/lexer.minimal.cjs`

The file is minified and contains encoded strings (base64 WASM, obfuscated identifiers). While this is common for distributed builds, it reduces auditability and can hide behavior.

### [low] Import-time code execution

Finding ID: `NPS-08EC88B3804C`

File: `dist/lexer.minimal.js`

Top-level code decodes the base64 WASM blob and calls WebAssembly.compile(...).then(...), so nontrivial code (WASM instantiation) executes simply upon importing this module, before any exported function is called.

## Files reviewed

- `dist/lexer.cjs` (medium): The file contains a heavily obfuscated WebAssembly payload and uses eval, which may hide malicious behavior, though no direct exfiltration or backdoor code is evident in the JavaScript layer.
- `dist/lexer.js` (medium): This appears to be the legitimate es-module-lexer package using embedded WebAssembly and a limited eval-based string unescape, but the eval on input-derived strings and embedded opaque WASM blob are noteworthy risk indicators rather than confirmed malicious behavior.
- `dist/lexer.minimal.cjs` (medium): This appears to be a legitimate minimal lexer/parser (likely from Babel/SWC) but contains risky patterns such as eval() on parsed source and an embedded WebAssembly module, warranting a warning rather than a safe classification.
- `dist/lexer.minimal.js` (medium): This appears to be the legitimate es-module-lexer package (v2.3.2) with its standard embedded WASM lexer and a localized eval() used to decode import specifiers; no exfiltration, credential harvesting, process spawning, or network access is present, but the embedded opaque WASM blob and eval usage warrant caution and version/integrity verification.
- `dist/lexer.asm.js` (safe): No malicious patterns detected; this is a legitimate WebAssembly-based JavaScript lexer (es-module-lexer) with no network, filesystem, process, or credential access.
- `dist/lexer.minimal.asm.js` (safe): This is the official es-module-lexer WebAssembly-based JavaScript lexer package (version 2.3.2); no malicious patterns, exfiltration, credential harvesting, or dynamic code execution were detected.
- `lexer.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
