Summary
Togoder Security scanned the npm package es6-promise@4.2.8 on Oct 4, 2026. An AI review of 16 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
Dynamic code execution
NPS-CAD019040FE1
The attemptVertx function uses Function('return this')().require('vertx') to dynamically access the global object and require a module. While this appears to be for legitimate Vert.x environment detection, the use of Function constructor for dynamic code execution is a security concern as it bypasses certain security restrictions and could be exploited in some contexts.
Dynamic code execution
NPS-2467047BCE34
Uses Function('return this')() to obtain the global object when global and self are undefined. While this is a known idiom in ES6 Promise polyfills, dynamic Function construction is a red flag and can be used to evade static analysis or execute arbitrary code if the pattern is modified.
dynamic code execution
NPS-618464A9C4DE
Uses Function('return this')() to obtain the global object in attemptVertx and polyfill. This is a known polyfill technique for accessing the global scope and is not user-controllable, but it is still dynamic code evaluation and warrants mention as a low-severity concern.
dynamic code execution
NPS-3783E36815D2
The attemptVertx function uses Function('return this')().require('vertx') to dynamically evaluate code and load a module via the global require. While this is a legitimate compatibility shim for the Vert.x environment and only triggers when running under Node-like conditions without a browser window, the use of new Function-style dynamic evaluation and runtime require of a non-static module name is a code pattern frequently abused by malicious packages and could be exploited if the environment is manipulated.
dynamic code execution
NPS-328444790E19
The polyfill function falls back to Function('return this')() to obtain the global object when neither global nor self are defined. This is dynamic code evaluation via the Function constructor. In this file it is used solely to retrieve the global object for polyfilling Promise, but such constructs can be used to escape sandboxes or execute arbitrary code if the environment is attacker-controlled.
Environment detection and branching
NPS-6374AE597E9A
The code performs extensive environment detection (Node.js, browser, web worker, Vert.x) and dynamically chooses scheduling strategies. While this is normal for a polyfill library, the complexity could potentially mask malicious behavior in a compromised package.
Global environment modification
NPS-6E3A33798FF2
The polyfill reassigns local.Promise, overwriting the native Promise implementation. This is expected polyfill behavior but means the module mutates a global built-in on import.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/es6-promise.js | medium | This is the legitimate es6-promise polyfill library; the only notable patterns are two uses of the Function constructor for environment detection, which are benign in context but worth flagging as low-severity dynamic code evaluation. |
| lib/es6-promise/asap.js | medium | This appears to be a legitimate asap (as soon as possible) scheduling polyfill from es6-promise, but contains a Function constructor usage for Vert.x detection that warrants caution. |
| lib/es6-promise/polyfill.js | medium | ES6 Promise polyfill contains a dynamic Function constructor call (a common but noteworthy idiom) and globally overwrites Promise; no exfiltration, credential harvesting, network, or process-spawning behavior is present. |
| auto.js | safe | No malicious patterns detected |
| dist/es6-promise.auto.js | safe | This is the well-known es6-promise polyfill library with no malicious patterns, data exfiltration, credential harvesting, backdoors, or process spawning; only benign polyfill techniques such as Function('return this') are present. |
| lib/es6-promise.auto.js | safe | No malicious patterns detected in this minimal polyfill wrapper file. |
| lib/es6-promise.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/-internal.js | safe | No malicious patterns detected; the code is a legitimate Promise implementation with no network, filesystem, process, or dynamic code execution concerns. |
| lib/es6-promise/enumerator.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/promise.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/promise/all.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/promise/race.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/promise/reject.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/promise/resolve.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/then.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/es6-promise/utils.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of es6-promise
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 4.2.8 | Needs review | 16 | Oct 4, 2026 |
Frequently asked questions
Is es6-promise safe to use?
No confirmed malware was found in es6-promise@4.2.8, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does es6-promise contain malware?
No malware was identified in es6-promise@4.2.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was es6-promise checked?
Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan es6-promise together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in es6-promise@4.2.8, cost nothing.