Togoder security

npm package security report

esbuild@0.24.2 security report

Risky patterns found that deserve a look.

Needs review Version 0.24.2 Files reviewed 2 Size 96.5 KB Scanned

Summary

Togoder Security scanned the npm package esbuild@0.24.2 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
2
low

Findings 4

medium

Network download and execution of binary

NPS-0C80FA87AEA2

The script downloads a platform-specific binary from the npm registry and executes it. While this is expected for esbuild, it involves fetching and running an external binary, which is a potential supply chain risk if the registry or package is compromised.

install.js
medium

Process spawning and command execution

NPS-F026E4DCE361

Uses child_process.execSync and execFileSync to run npm install and execute the downloaded binary. This is typical for install scripts but can be abused if inputs are not properly validated.

install.js
low

File system manipulation

NPS-B28E0C2ACC33

Writes, renames, and deletes files within the package directory and creates temporary directories. This is standard for install scripts but could be leveraged for malicious purposes if the package is compromised.

install.js
low

Environment variable usage

NPS-02EA55A8436D

Reads ESBUILD_BINARY_PATH and npm_config_user_agent environment variables. This is not inherently malicious, but environment variables can be used to alter behavior.

install.js

Files reviewed

FileVerdictWhat the reviewer saw
install.js medium The install script for esbuild performs expected operations such as downloading and executing a platform-specific binary, but these actions carry inherent supply chain and execution risks.
lib/main.js safe No malicious patterns detected; this is the legitimate esbuild npm package's JavaScript API layer, which spawns the esbuild binary as expected behavior.

Affected version ranges

None of the 2 scanned versions of esbuild are flagged high or critical. The latest scanned version, 0.28.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.24.20.28.2
VersionsVerdictCountRangeTop findings
0.28.2 Needs review 1 0.28.2 Code execution via child_process; Network download and file write
0.25.8 โ€“ 0.28.1 Not scanned 4 >=0.25.8 <=0.28.1
0.24.2 Needs review 1 0.24.2 Network download and execution of binary; Process spawning and command execution

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of esbuild

VersionVerdictFilesScanned
0.28.2 Needs review 2 Oct 6, 2026
0.24.2 Needs review 2 Oct 4, 2026

Frequently asked questions

Is esbuild safe to use?

No confirmed malware was found in esbuild@0.24.2, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does esbuild contain malware?

No malware was identified in esbuild@0.24.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was esbuild checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan esbuild together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in esbuild@0.24.2, cost nothing.

Related security reports