# esbuild@0.24.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:29:13.000Z
- Files reviewed: 2
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/esbuild@0.24.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package esbuild@0.24.2 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Network download and execution of binary

Finding ID: `NPS-0C80FA87AEA2`

File: `install.js`

The script downloads a platform-specific binary from the npm registry and executes it. While this is expected for esbuild, it involves fetching and running an external binary, which is a potential supply chain risk if the registry or package is compromised.

### [medium] Process spawning and command execution

Finding ID: `NPS-F026E4DCE361`

File: `install.js`

Uses child_process.execSync and execFileSync to run npm install and execute the downloaded binary. This is typical for install scripts but can be abused if inputs are not properly validated.

### [low] File system manipulation

Finding ID: `NPS-B28E0C2ACC33`

File: `install.js`

Writes, renames, and deletes files within the package directory and creates temporary directories. This is standard for install scripts but could be leveraged for malicious purposes if the package is compromised.

### [low] Environment variable usage

Finding ID: `NPS-02EA55A8436D`

File: `install.js`

Reads ESBUILD_BINARY_PATH and npm_config_user_agent environment variables. This is not inherently malicious, but environment variables can be used to alter behavior.

## Files reviewed

- `install.js` (medium): The install script for esbuild performs expected operations such as downloading and executing a platform-specific binary, but these actions carry inherent supply chain and execution risks.
- `lib/main.js` (safe): No malicious patterns detected; this is the legitimate esbuild npm package's JavaScript API layer, which spawns the esbuild binary as expected behavior.

## Version ranges

None of the 2 scanned versions of esbuild are flagged high or critical. The latest scanned version, 0.28.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 0.28.2 (`0.28.2`): medium (Code execution via child_process +4 more)
- 0.25.8 – 0.28.1 (`>=0.25.8 <=0.28.1`): not scanned
- 0.24.2 (`0.24.2`): medium (Network download and execution of binary +1 more)

## Scanned versions

- [0.28.2](https://security.togoder.click/npm/esbuild@0.28.2): medium, 2026-10-06T14:16:15.000Z
- [0.24.2](https://security.togoder.click/npm/esbuild@0.24.2): medium, 2026-10-04T16:29:13.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
