Summary
Togoder Security scanned the npm package eslint-plugin-import@2.32.0 on Oct 6, 2026. An AI review of 76 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic code execution
NPS-4F90B9C9DF7F
Uses vm.runInNewContext to evaluate a string constructed from ESLint block comment contents. While the intent is to mirror webpack's comment parsing, invoking a VM on comment text is a dynamic code execution pattern. The generated code is wrapped in an object literal, but the input is file content controlled by the project being linted, so it is an unnecessary and risk-prone use of a sandbox evaluator in a lint rule.
No malicious patterns detected
NPS-90008CDD6017
This file is part of eslint-plugin-import and contains only legitimate module import type resolution logic. It uses standard Node.js path utilities and package resolution helpers. No data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, network requests, process spawning, or install-time hooks are present.
ESLint rule definition
NPS-DAE185BAAE44
This file is a standard ESLint rule implementation for forbidding Node.js builtin module imports. It uses common ESLint patterns: requiring utility modules, defining meta/schema, and reporting lint violations with context.report. No network, filesystem, process, eval, or credential access is present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/rules/dynamic-import-chunkname.js | medium | No exfiltration, credential harvesting, network, or process execution behavior, but the rule uses vm.runInNewContext on comment text, a dynamic execution pattern that warrants review. |
| config/electron.js | safe | Cleared by Jev triage; no further analysis needed |
| config/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| config/flat/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| config/flat/react.js | safe | Cleared by Jev triage; no further analysis needed |
| config/flat/recommended.js | safe | Cleared by Jev triage; no further analysis needed |
| config/flat/warnings.js | safe | Cleared by Jev triage; no further analysis needed |
| config/react-native.js | safe | Cleared by Jev triage; no further analysis needed |
| config/react.js | safe | Cleared by Jev triage; no further analysis needed |
| config/recommended.js | safe | Cleared by Jev triage; no further analysis needed |
| config/stage-0.js | safe | Cleared by Jev triage; no further analysis needed |
| config/typescript.js | safe | Cleared by Jev triage; no further analysis needed |
| config/warnings.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/core/importType.js | safe | The code is a standard ESLint plugin utility for classifying import types with no security concerns. |
| lib/core/packagePath.js | safe | No malicious patterns detected |
| lib/core/sourceType.js | safe | No malicious patterns detected |
| lib/core/staticRequire.js | safe | No malicious patterns detected; the code is a benign AST utility that checks for static require() calls. |
| lib/docsUrl.js | safe | No malicious patterns detected; the file is a simple utility that generates documentation URLs from the package version. |
| lib/exportMap/builder.js | safe | No malicious patterns detected; this is a standard ESLint plugin module for building export maps of JavaScript/TypeScript files. |
| lib/exportMap/captureDependency.js | safe | No malicious patterns detected; this is legitimate dependency-tracking code from a static analysis tool that only parses and stores import metadata. |
| lib/exportMap/childContext.js | safe | The code is a legitimate ESLint utility for computing cache keys from parser/settings context, with no malicious patterns detected. |
| lib/exportMap/doc.js | safe | No malicious patterns detected |
| lib/exportMap/index.js | safe | No malicious patterns detected; the file is a Babel-compiled ES module for an ESLint import resolver, containing no network, filesystem, process, or dynamic-eval functionality. |
| lib/exportMap/namespace.js | safe | No malicious patterns detected; the code implements a namespace resolver using local relative imports and no network, filesystem, or process execution. |
| lib/exportMap/patternCapture.js | safe | No malicious patterns detected; the code is a benign AST pattern traversal utility with no network, filesystem, or process activity. |
Show 51 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/exportMap/remotePath.js | safe | No malicious patterns detected |
| lib/exportMap/specifier.js | safe | No malicious patterns detected; the code is a standard ES module specifier processor for building export maps. |
| lib/exportMap/typescript.js | safe | No malicious patterns detected; the file legitimately reads TypeScript configuration and caches the result for the ESLint import plugin. |
| lib/exportMap/visitor.js | safe | This is a legitimate ESLint import/export analysis module with no malicious patterns detected. |
| lib/importDeclaration.js | safe | No malicious patterns detected; the file is a simple ESLint helper that returns the last ancestor of a node. |
| lib/index.js | safe | No malicious patterns detected; the file is a standard ESLint plugin entry point that statically requires local rule and config modules. |
| lib/rules/consistent-type-specifier-style.js | safe | This is a standard ESLint rule implementation for consistent type specifier style; no malicious patterns, network activity, credential access, or dynamic code execution were detected. |
| lib/rules/default.js | safe | No malicious patterns detected; the file is a legitimate ESLint rule definition that checks for default exports. |
| lib/rules/enforce-node-protocol-usage.js | safe | No malicious patterns detected |
| lib/rules/export.js | safe | No malicious patterns detected; the code is a standard ESLint rule for validating exports and contains only expected logic for processing AST nodes. |
| lib/rules/exports-last.js | safe | No malicious patterns detected |
| lib/rules/extensions.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation with no data exfiltration, obfuscation, or suspicious behavior. |
| lib/rules/first.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation for enforcing import ordering with no network, file system, or process execution activity. |
| lib/rules/group-exports.js | safe | No malicious patterns detected in this ESLint rule implementation for grouping exports. |
| lib/rules/imports-first.js | safe | No malicious patterns detected; the file is a simple ESLint rule deprecation wrapper with no network, filesystem, or execution risks. |
| lib/rules/max-dependencies.js | safe | No malicious patterns detected |
| lib/rules/named.js | safe | No malicious patterns detected |
| lib/rules/namespace.js | safe | No malicious patterns detected in this ESLint rule implementation; the code performs static analysis of import namespaces and contains no network, filesystem, process, or dynamic execution activities. |
| lib/rules/newline-after-import.js | safe | This is a standard ESLint rule for enforcing newlines after import statements, with no network, filesystem, process, or obfuscation patterns indicating malicious behavior. |
| lib/rules/no-absolute-path.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation with only benign path manipulation and static analysis logic. |
| lib/rules/no-amd.js | safe | No malicious patterns detected; this is a legitimate ESLint rule that forbids AMD require/define calls. |
| lib/rules/no-anonymous-default-export.js | safe | No malicious patterns detected |
| lib/rules/no-commonjs.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation for forbidding CommonJS syntax. |
| lib/rules/no-cycle.js | safe | This is a legitimate ESLint rule implementation for detecting circular dependencies, with no malicious patterns detected. |
| lib/rules/no-default-export.js | safe | This is a benign ESLint rule implementation for forbidding default exports, with no malicious patterns detected. |
| lib/rules/no-deprecated.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation for flagging deprecated imports. |
| lib/rules/no-duplicates.js | safe | No malicious patterns detected |
| lib/rules/no-dynamic-require.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation that forbids dynamic require() calls. |
| lib/rules/no-empty-named-blocks.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation with no network, filesystem, process, or obfuscation concerns. |
| lib/rules/no-extraneous-dependencies.js | safe | This is a standard ESLint rule implementation for checking extraneous dependencies; no malicious patterns, data exfiltration, credential harvesting, obfuscated code, or suspicious behavior was detected. |
| lib/rules/no-import-module-exports.js | safe | No malicious patterns detected |
| lib/rules/no-internal-modules.js | safe | This is a standard ESLint rule implementation for enforcing module import boundaries with no malicious patterns detected. |
| lib/rules/no-mutable-exports.js | safe | No malicious patterns detected |
| lib/rules/no-named-as-default-member.js | safe | This is a standard ESLint rule implementation from eslint-plugin-import that analyzes import statements for helpful warnings; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution were detected. |
| lib/rules/no-named-as-default.js | safe | No malicious patterns detected |
| lib/rules/no-named-default.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation with no network, filesystem, or dynamic code execution activity. |
| lib/rules/no-named-export.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation for forbidding named exports. |
| lib/rules/no-namespace.js | safe | This is a standard ESLint rule implementation with no malicious patterns; it performs static AST analysis and text fixes only. |
| lib/rules/no-nodejs-modules.js | safe | Legitimate ESLint rule implementation with no malicious patterns detected. |
| lib/rules/no-relative-packages.js | safe | No malicious patterns detected; the file is a standard ESLint rule for enforcing package import best practices. |
| lib/rules/no-relative-parent-imports.js | safe | No malicious patterns detected |
| lib/rules/no-restricted-paths.js | safe | No malicious patterns detected; the file is a standard ESLint rule for restricting import paths with no network, filesystem, process execution, or obfuscated code. |
| lib/rules/no-self-import.js | safe | No malicious patterns detected |
| lib/rules/no-unassigned-import.js | safe | No malicious patterns detected |
| lib/rules/no-unresolved.js | safe | No malicious patterns detected; the code is a standard ESLint rule that resolves import paths and checks filesystem casing. |
| lib/rules/no-useless-path-segments.js | safe | No malicious patterns detected; this is a legitimate ESLint rule implementation for detecting useless path segments in imports. |
| lib/rules/no-webpack-loader-syntax.js | safe | No malicious patterns detected |
| lib/rules/prefer-default-export.js | safe | This is a standard ESLint rule implementation with no malicious patterns, network requests, credential harvesting, or dynamic code execution. |
| lib/rules/unambiguous.js | safe | No malicious patterns detected |
| lib/scc.js | safe | No malicious patterns detected; the code is a standard ESLint module dependency graph builder with caching and no network, file system, or process manipulation. |
| memo-parser/index.js | safe | No malicious patterns detected; the code is a legitimate ESLint parser cache wrapper that uses hashing and module loading without any suspicious behavior. |
Frequently asked questions
Is eslint-plugin-import safe to use?
No confirmed malware was found in eslint-plugin-import@2.32.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does eslint-plugin-import contain malware?
No malware was identified in eslint-plugin-import@2.32.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was eslint-plugin-import checked?
Togoder Security downloaded the published npm package and had an AI model read its 76 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan eslint-plugin-import together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eslint-plugin-import@2.32.0, cost nothing.