Togoder security

npm package security report

es6-promise@4.2.8 security report

Risky patterns found that deserve a look.

Needs review Version 4.2.8 Files reviewed 16 Size 85.9 KB Scanned

Summary

Togoder Security scanned the npm package es6-promise@4.2.8 on Oct 4, 2026. An AI review of 16 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
5
low

Findings 7

medium

Dynamic code execution

NPS-CAD019040FE1

The attemptVertx function uses Function('return this')().require('vertx') to dynamically access the global object and require a module. While this appears to be for legitimate Vert.x environment detection, the use of Function constructor for dynamic code execution is a security concern as it bypasses certain security restrictions and could be exploited in some contexts.

lib/es6-promise/asap.js:78
medium

Dynamic code execution

NPS-2467047BCE34

Uses Function('return this')() to obtain the global object when global and self are undefined. While this is a known idiom in ES6 Promise polyfills, dynamic Function construction is a red flag and can be used to evade static analysis or execute arbitrary code if the pattern is modified.

lib/es6-promise/polyfill.js:11
low

dynamic code execution

NPS-618464A9C4DE

Uses Function('return this')() to obtain the global object in attemptVertx and polyfill. This is a known polyfill technique for accessing the global scope and is not user-controllable, but it is still dynamic code evaluation and warrants mention as a low-severity concern.

dist/es6-promise.auto.js
low

dynamic code execution

NPS-3783E36815D2

The attemptVertx function uses Function('return this')().require('vertx') to dynamically evaluate code and load a module via the global require. While this is a legitimate compatibility shim for the Vert.x environment and only triggers when running under Node-like conditions without a browser window, the use of new Function-style dynamic evaluation and runtime require of a non-static module name is a code pattern frequently abused by malicious packages and could be exploited if the environment is manipulated.

dist/es6-promise.js:152
low

dynamic code execution

NPS-328444790E19

The polyfill function falls back to Function('return this')() to obtain the global object when neither global nor self are defined. This is dynamic code evaluation via the Function constructor. In this file it is used solely to retrieve the global object for polyfilling Promise, but such constructs can be used to escape sandboxes or execute arbitrary code if the environment is attacker-controlled.

dist/es6-promise.js:1006
low

Environment detection and branching

NPS-6374AE597E9A

The code performs extensive environment detection (Node.js, browser, web worker, Vert.x) and dynamically chooses scheduling strategies. While this is normal for a polyfill library, the complexity could potentially mask malicious behavior in a compromised package.

lib/es6-promise/asap.js
low

Global environment modification

NPS-6E3A33798FF2

The polyfill reassigns local.Promise, overwriting the native Promise implementation. This is expected polyfill behavior but means the module mutates a global built-in on import.

lib/es6-promise/polyfill.js:30

Files reviewed

FileVerdictWhat the reviewer saw
dist/es6-promise.js medium This is the legitimate es6-promise polyfill library; the only notable patterns are two uses of the Function constructor for environment detection, which are benign in context but worth flagging as low-severity dynamic code evaluation.
lib/es6-promise/asap.js medium This appears to be a legitimate asap (as soon as possible) scheduling polyfill from es6-promise, but contains a Function constructor usage for Vert.x detection that warrants caution.
lib/es6-promise/polyfill.js medium ES6 Promise polyfill contains a dynamic Function constructor call (a common but noteworthy idiom) and globally overwrites Promise; no exfiltration, credential harvesting, network, or process-spawning behavior is present.
auto.js safe No malicious patterns detected
dist/es6-promise.auto.js safe This is the well-known es6-promise polyfill library with no malicious patterns, data exfiltration, credential harvesting, backdoors, or process spawning; only benign polyfill techniques such as Function('return this') are present.
lib/es6-promise.auto.js safe No malicious patterns detected in this minimal polyfill wrapper file.
lib/es6-promise.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/-internal.js safe No malicious patterns detected; the code is a legitimate Promise implementation with no network, filesystem, process, or dynamic code execution concerns.
lib/es6-promise/enumerator.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/promise.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/promise/all.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/promise/race.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/promise/reject.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/promise/resolve.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/then.js safe Cleared by Jev triage; no further analysis needed
lib/es6-promise/utils.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is es6-promise safe to use?

No confirmed malware was found in es6-promise@4.2.8, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does es6-promise contain malware?

No malware was identified in es6-promise@4.2.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was es6-promise checked?

Togoder Security downloaded the published npm package and had an AI model read its 16 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan es6-promise together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in es6-promise@4.2.8, cost nothing.

Related security reports