Summary
Togoder Security scanned the npm package esbuild@0.24.2 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Network download and execution of binary
NPS-0C80FA87AEA2
The script downloads a platform-specific binary from the npm registry and executes it. While this is expected for esbuild, it involves fetching and running an external binary, which is a potential supply chain risk if the registry or package is compromised.
Process spawning and command execution
NPS-F026E4DCE361
Uses child_process.execSync and execFileSync to run npm install and execute the downloaded binary. This is typical for install scripts but can be abused if inputs are not properly validated.
File system manipulation
NPS-B28E0C2ACC33
Writes, renames, and deletes files within the package directory and creates temporary directories. This is standard for install scripts but could be leveraged for malicious purposes if the package is compromised.
Environment variable usage
NPS-02EA55A8436D
Reads ESBUILD_BINARY_PATH and npm_config_user_agent environment variables. This is not inherently malicious, but environment variables can be used to alter behavior.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| install.js | medium | The install script for esbuild performs expected operations such as downloading and executing a platform-specific binary, but these actions carry inherent supply chain and execution risks. |
| lib/main.js | safe | No malicious patterns detected; this is the legitimate esbuild npm package's JavaScript API layer, which spawns the esbuild binary as expected behavior. |
Affected version ranges
None of the 2 scanned versions of esbuild are flagged high or critical. The latest scanned version, 0.28.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 0.28.2 | Needs review | 1 | 0.28.2 | Code execution via child_process; Network download and file write |
| 0.25.8 โ 0.28.1 | Not scanned | 4 | >=0.25.8 <=0.28.1 | |
| 0.24.2 | Needs review | 1 | 0.24.2 | Network download and execution of binary; Process spawning and command execution |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of esbuild
Frequently asked questions
Is esbuild safe to use?
No confirmed malware was found in esbuild@0.24.2, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does esbuild contain malware?
No malware was identified in esbuild@0.24.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was esbuild checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan esbuild together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in esbuild@0.24.2, cost nothing.