# es6-promise@4.2.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:28:57.000Z
- Files reviewed: 16
- Findings: 2 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/es6-promise
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package es6-promise@4.2.8 on Oct 4, 2026. An AI review of 16 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-CAD019040FE1`

File: `lib/es6-promise/asap.js:78`

The attemptVertx function uses Function('return this')().require('vertx') to dynamically access the global object and require a module. While this appears to be for legitimate Vert.x environment detection, the use of Function constructor for dynamic code execution is a security concern as it bypasses certain security restrictions and could be exploited in some contexts.

### [medium] Dynamic code execution

Finding ID: `NPS-2467047BCE34`

File: `lib/es6-promise/polyfill.js:11`

Uses Function('return this')() to obtain the global object when global and self are undefined. While this is a known idiom in ES6 Promise polyfills, dynamic Function construction is a red flag and can be used to evade static analysis or execute arbitrary code if the pattern is modified.

### [low] dynamic code execution

Finding ID: `NPS-618464A9C4DE`

File: `dist/es6-promise.auto.js`

Uses Function('return this')() to obtain the global object in attemptVertx and polyfill. This is a known polyfill technique for accessing the global scope and is not user-controllable, but it is still dynamic code evaluation and warrants mention as a low-severity concern.

### [low] dynamic code execution

Finding ID: `NPS-3783E36815D2`

File: `dist/es6-promise.js:152`

The `attemptVertx` function uses `Function('return this')().require('vertx')` to dynamically evaluate code and load a module via the global `require`. While this is a legitimate compatibility shim for the Vert.x environment and only triggers when running under Node-like conditions without a browser window, the use of `new Function`-style dynamic evaluation and runtime `require` of a non-static module name is a code pattern frequently abused by malicious packages and could be exploited if the environment is manipulated.

### [low] dynamic code execution

Finding ID: `NPS-328444790E19`

File: `dist/es6-promise.js:1006`

The `polyfill` function falls back to `Function('return this')()` to obtain the global object when neither `global` nor `self` are defined. This is dynamic code evaluation via the Function constructor. In this file it is used solely to retrieve the global object for polyfilling `Promise`, but such constructs can be used to escape sandboxes or execute arbitrary code if the environment is attacker-controlled.

### [low] Environment detection and branching

Finding ID: `NPS-6374AE597E9A`

File: `lib/es6-promise/asap.js`

The code performs extensive environment detection (Node.js, browser, web worker, Vert.x) and dynamically chooses scheduling strategies. While this is normal for a polyfill library, the complexity could potentially mask malicious behavior in a compromised package.

### [low] Global environment modification

Finding ID: `NPS-6E3A33798FF2`

File: `lib/es6-promise/polyfill.js:30`

The polyfill reassigns local.Promise, overwriting the native Promise implementation. This is expected polyfill behavior but means the module mutates a global built-in on import.

## Files reviewed

- `dist/es6-promise.js` (medium): This is the legitimate es6-promise polyfill library; the only notable patterns are two uses of the Function constructor for environment detection, which are benign in context but worth flagging as low-severity dynamic code evaluation.
- `lib/es6-promise/asap.js` (medium): This appears to be a legitimate asap (as soon as possible) scheduling polyfill from es6-promise, but contains a Function constructor usage for Vert.x detection that warrants caution.
- `lib/es6-promise/polyfill.js` (medium): ES6 Promise polyfill contains a dynamic Function constructor call (a common but noteworthy idiom) and globally overwrites Promise; no exfiltration, credential harvesting, network, or process-spawning behavior is present.
- `auto.js` (safe): No malicious patterns detected
- `dist/es6-promise.auto.js` (safe): This is the well-known es6-promise polyfill library with no malicious patterns, data exfiltration, credential harvesting, backdoors, or process spawning; only benign polyfill techniques such as Function('return this') are present.
- `lib/es6-promise.auto.js` (safe): No malicious patterns detected in this minimal polyfill wrapper file.
- `lib/es6-promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/-internal.js` (safe): No malicious patterns detected; the code is a legitimate Promise implementation with no network, filesystem, process, or dynamic code execution concerns.
- `lib/es6-promise/enumerator.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/promise/all.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/promise/race.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/promise/reject.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/promise/resolve.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/then.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/es6-promise/utils.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
