Togoder security

npm package security report

eslint-module-utils@2.14.0 security report

Risky patterns found that deserve a look.

Needs review Version 2.14.0 Files reviewed 14 Size 36.1 KB Scanned

Summary

Togoder Security scanned the npm package eslint-module-utils@2.14.0 on Oct 6, 2026. An AI review of 14 source files produced 4 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
5
low

Findings 9

medium

Dynamic module loading with computed input

NPS-4207CFBE968F

The moduleRequire function accepts an arbitrary package/module name parameter 'p' and dynamically resolves and requires it using Module._resolveFilename with an internals module. This could allow loading of modules from unexpected locations or paths if 'p' is attacker-controlled, bypassing normal resolution boundaries.

module-require.js:24
medium

Dynamic import fallback chain

NPS-5F6F9C7491D2

Falls back to require.main.require(p) and finally require(p) with the same external input, increasing chances of arbitrary module resolution/loading depending on caller-supplied values.

module-require.js:31
medium

Dynamic module loading based on external configuration

NPS-DFE3301D286D

The parse function uses moduleRequire(parserOrPath) where parserOrPath can be a string derived from ESLint settings ('import/parsers' or context.parserPath). This allows loading arbitrary modules specified in configuration, which could be exploited if an attacker can control ESLint settings to load a malicious module.

parse.js:170
medium

Dynamic module loading

NPS-0007316E04DB

The code dynamically loads resolver modules based on user configuration via requireResolver(), using tryRequire() with paths derived from configuration. It attempts to require 'eslint-import-resolver-<name>', the raw name, and a path resolved relative to the base directory. This dynamic loading of arbitrary modules based on configuration could be abused if the configuration is attacker-controlled, allowing loading of malicious modules.

resolve.js:100
low

Use of undocumented Node.js internals

NPS-327AA5CEDB96

Uses Module._nodeModulePaths and Module._resolveFilename, undocumented internal APIs that may change between Node versions and can bypass standard module resolution/security checks. Could be leveraged for path traversal or loading modules outside intended scope.

module-require.js:14
low

Dynamic module loading with computed path

NPS-9F2955038058

The function getBabelEslintVisitorKeys constructs a file path by replacing 'index.js' with 'visitor-keys.js' in a given parserPath and then dynamically requires it. This could allow loading arbitrary modules if the parserPath is attacker-controlled, though in context it is derived from ESLint settings.

parse.js:17
low

Top-level code execution on import

NPS-E3CB3C4C6B26

The module performs computation and filesystem checks at import time (CASE_SENSITIVE_FS detection via fs.existsSync, and initialization of ModuleCache). This is typical for a library but does execute code upon import.

resolve.js:13
low

Dynamic code compilation

NPS-6B4747D115E9

A fallback implementation of createRequire uses Module._compile() to compile and execute dynamically generated code ('module.exports = require;'). While this is a polyfill for older Node versions and only compiles a static string, the use of _compile is a dynamic code execution primitive that could be risky if the filename/path were attacker-controlled.

resolve.js:33
low

Filesystem traversal

NPS-770C12B00A38

fileExistsWithCaseSync recursively reads directories using fs.readdirSync to determine case-sensitivity of paths. This is within the scope of resolving module paths and is not outside package scope, but it does perform filesystem access.

resolve.js:140

Files reviewed

FileVerdictWhat the reviewer saw
module-require.js medium This utility dynamically resolves and loads arbitrary modules using Node internals and caller-supplied input, which is a supply-chain risk if the input is ever attacker-controlled, though no direct exfiltration, credential harvesting, or execution backdoors are present.
parse.js medium The code is a legitimate ESLint plugin utility for parsing, but it dynamically requires modules based on external configuration, which could be a security risk if settings are untrusted.
resolve.js medium The code is a legitimate ESLint import resolver plugin with dynamic module loading and a Module._compile polyfill, which are not inherently malicious but could be abused if configuration is attacker-controlled.
ModuleCache.js safe Cleared by Jev triage; no further analysis needed
contextCompat.js safe Cleared by Jev triage; no further analysis needed
declaredScope.js safe Cleared by Jev triage; no further analysis needed
hash.js safe Cleared by Jev triage; no further analysis needed
ignore.js safe No malicious patterns detected; the file contains legitimate ESLint plugin utility logic for handling ignore patterns and file extensions.
moduleVisitor.js safe Cleared by Jev triage; no further analysis needed
pkgDir.js safe Cleared by Jev triage; no further analysis needed
pkgUp.js safe Cleared by Jev triage; no further analysis needed
readPkgUp.js safe No malicious patterns detected; the code only reads and parses package.json files via a local helper module.
unambiguous.js safe Cleared by Jev triage; no further analysis needed
visit.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is eslint-module-utils safe to use?

No confirmed malware was found in eslint-module-utils@2.14.0, but the review flagged 4 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does eslint-module-utils contain malware?

No malware was identified in eslint-module-utils@2.14.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was eslint-module-utils checked?

Togoder Security downloaded the published npm package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan eslint-module-utils together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eslint-module-utils@2.14.0, cost nothing.

Related security reports