Togoder security

npm package security report

esbuild npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.28.2 Files reviewed 2 Size 106.7 KB Scanned

Summary

Togoder Security scanned the npm package esbuild@0.28.2 on Oct 6, 2026. An AI review of 2 source files produced 5 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
5
medium
4
low

Findings 9

medium

Code execution via child_process

NPS-6BD6E77A0E55

The script uses child_process.execFileSync and execSync to spawn external commands (validateBinaryVersion runs the esbuild binary with --version; installUsingNPM runs 'npm install ...'). While these are expected for an install script, they still execute external binaries/commands.

install.js
medium

Network download and file write

NPS-9C470284E469

downloadDirectlyFromNPM fetches a .tgz from registry.npmjs.org and writes the extracted binary to disk with chmod 493. The download is over HTTPS and integrity is checked via SHA-256 against package.json hashes, but it is still remote code/binary fetching.

install.js
medium

File system manipulation outside package scope

NPS-B7F4CAF9B2CF

installUsingNPM creates a temporary directory inside the esbuild package directory, runs npm install there, then renames the installed binary into place. applyManualBinaryPathOverride overwrites bin/esbuild and modifies lib/main.js when ESBUILD_BINARY_PATH is set. These write operations are scoped to the package but modify installed files.

install.js
medium

Environment variable usage

NPS-F4A7B1218A91

The script reads process.env.ESBUILD_BINARY_PATH and process.env.npm_config_user_agent. If ESBUILD_BINARY_PATH is set and valid, applyManualBinaryPathOverride rewrites package files to execute an arbitrary user-specified binary path. This is a documented feature but can be abused if an attacker controls that env var.

install.js
medium

Install-time execution

NPS-C8DD1341969C

All of the above logic runs at module load time (top-level await of checkAndPreparePackage). This is typical for an npm install script, but it means any import of this file triggers network and process execution.

install.js
low

Process spawning and dynamic binary resolution

NPS-3BE5C29C929A

The code spawns child processes using child_process.spawn and child_process.execFileSync to run the platform-specific esbuild binary. The binary path is resolved dynamically via generateBinPath(), which enumerates platform-specific packages, checks ESBUILD_BINARY_PATH environment variable, and falls back to copying binaries. While this is legitimate esbuild behavior, the dynamic binary resolution and execution flow is inherent to esbuild's architecture and is a potential vector if the environment variable or package resolution is manipulated.

lib/main.js
low

Environment variable usage

NPS-0D0C21FB0753

The code reads process.env.ESBUILD_BINARY_PATH and process.env.ESBUILD_WORKER_THREADS to configure execution. The ESBUILD_BINARY_PATH override allows an attacker with control over the environment to direct execution to an arbitrary binary. This is a documented feature but represents a potential privilege escalation or code execution vector in compromised environments.

lib/main.js
low

Worker thread and SharedArrayBuffer usage

NPS-460C68B2D8D9

The code starts a worker thread using the current filename (__filename) and uses SharedArrayBuffer with Atomics for synchronous communication. Worker threads spawn additional processes and evaluate incoming messages. While this is standard for esbuild's synchronous API, it increases the attack surface for code execution if messages can be tampered with.

lib/main.js
low

Dynamic module resolution

NPS-DD624D3B86D9

The code uses require.resolve() extensively with computed package names to locate platform-specific binaries. It also attempts to require('pnpapi') and require('worker_threads') dynamically. While legitimate, dynamic require with computed paths can be abused if package resolution is poisoned.

lib/main.js

Files reviewed

FileVerdictWhat the reviewer saw
install.js medium This is the legitimate esbuild install script that downloads and installs the platform-specific binary with SHA-256 integrity verification; no clear malicious patterns were found, but it does perform install-time network fetches, process spawning, and filesystem writes typical of a binary installer.
lib/main.js medium The code is the legitimate esbuild packaging layer (version 0.28.2) that does not exhibit malicious patterns, though it does contain dynamic process spawning, environment variable usage, and worker thread creation inherent to its build-tool functionality.

Affected version ranges

None of the 2 scanned versions of esbuild are flagged high or critical. The latest scanned version, 0.28.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.24.20.28.2
VersionsVerdictCountRangeTop findings
0.28.2 Needs review 1 0.28.2 Code execution via child_process; Network download and file write
0.25.8 โ€“ 0.28.1 Not scanned 4 >=0.25.8 <=0.28.1
0.24.2 Needs review 1 0.24.2 Network download and execution of binary; Process spawning and command execution

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of esbuild

VersionVerdictFilesScanned
0.28.2 Needs review 2 Oct 6, 2026
0.24.2 Needs review 2 Oct 4, 2026

Frequently asked questions

Is esbuild safe to use?

No confirmed malware was found in esbuild@0.28.2, but the review flagged 5 medium, 4 low severity findings for risky patterns worth checking before you rely on it.

Does esbuild contain malware?

No malware was identified in esbuild@0.28.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was esbuild checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan esbuild together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in esbuild@0.28.2, cost nothing.

Related security reports