Summary
Togoder Security scanned the npm package execa@10.0.1 on Oct 6, 2026. An AI review of 109 source files produced 2 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Spawning processes or shell commands
NPS-5E4A35DD28C8
The code constructs and executes Windows command lines via cmd.exe with 'windowsVerbatimArguments' enabled and manual escaping logic. While the escaping appears intentional and defensive (rejecting CR/LF, caret-escaping metacharacters), this pattern is inherently high-risk and could enable command injection if any escaping edge case is missed or if an attacker can influence the file path or arguments.
Shell command concatenation without escaping
NPS-AEA9C3571874
The concatenateShell function joins file and its arguments with spaces into a single shell command string when options.shell is enabled. This replicates Node.js's internal shell concatenation but performs no quoting, escaping, or validation. If any argument originates from untrusted input, it can be interpreted by the shell (command injection, argument injection, or option injection). While the code itself does not exfiltrate data or spawn processes directly, it deliberately constructs shell-parsed command strings, which is a dangerous pattern when callers pass user-controlled values.
File system read outside package scope
NPS-5F0CFD34FFB0
readShebang opens and reads the first 150 bytes of arbitrary resolved files to parse shebang interpreters. This is expected for command resolution but does involve reading files outside the package boundary.
Environment variable harvesting
NPS-616BE54A33D8
The code reads PATH, PATHEXT, comspec, and NODEFAULTCURRENTDIRECTORYINEXEPATH environment variables. These are standard for Windows command resolution and are not credential-related, but environment access is present.
Dynamic path resolution using external inputs
NPS-D2EBF067A10D
whichCommandSync is used with user-supplied file/command names to resolve executables from PATH/PATHEXT. This can cause execution of unexpected binaries if the environment is attacker-controlled, though it is standard behavior for command launchers.
Process spawning
NPS-1602732130CC
Uses child_process.spawn to execute subprocesses, but this is the core purpose of the execa library and arguments are normalized through internal handlers; no unsanitized user input or external dynamic commands are present.
ChildProcess import
NPS-05FEAE71C8C2
The file imports ChildProcess from 'node:child_process', but only uses it for type checking (instanceof) to validate template expressions, not for executing commands.
Process Spawning
NPS-AFAF96020C3B
The code uses child_process.execFile to spawn taskkill.exe on Windows for terminating process trees. This is a legitimate use case for process termination and not a malicious pattern. The executable path is derived from environment variables (SystemRoot/windir) and validated to be a Windows drive absolute path before joining with System32\taskkill.exe.
Environment Variable Usage
NPS-9986573E60F7
Reads SystemRoot and windir environment variables to locate taskkill.exe on Windows. This is standard practice for locating system executables and does not constitute credential harvesting.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/arguments/command-file.js | medium | The file implements Windows command-line escaping and resolution for a well-known package (execa); it contains no exfiltration, credential theft, obfuscation, or backdoor patterns, but does spawn cmd.exe and read environment/filesystem paths in ways that warrant a warning-level review. |
| lib/arguments/shell.js | medium | The code safely normalizes shell argument handling but performs unescaped string concatenation for shell execution, creating a potential command-injection risk depending on caller-supplied arguments. |
| index.js | safe | This is the public entry point for the execa package, containing only standard imports/exports with no malicious patterns, obfuscation, or suspicious behavior. |
| lib/arguments/command.js | safe | No malicious patterns detected |
| lib/arguments/cwd.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/encoding-option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/escape.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/fd-options.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/file-url.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/options.js | safe | No malicious patterns detected; the code performs standard option normalization for a child process library with explicit prototype pollution protections. |
| lib/arguments/specific.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/add.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/concurrent.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/duplex.js | safe | No malicious patterns detected; the code only constructs a Node.js Duplex stream wrapper around a subprocess with no external network, filesystem, or process-spawning behavior. |
| lib/convert/iterable.js | safe | No malicious patterns detected; the code is a straightforward async iterable converter for subprocess stdout streams. |
| lib/convert/readable.js | safe | No malicious patterns detected |
| lib/convert/shared.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/web.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/writable.js | safe | No malicious patterns detected in the writable stream conversion module; it only handles subprocess I/O forwarding without any suspicious behavior. |
| lib/io/contents.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/input-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/iterate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/max-buffer.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/output-async.js | safe | No malicious patterns detected; the module only handles stream piping for subprocess I/O with no external network, credential, or code execution activities. |
| lib/io/output-sync.js | safe | No malicious patterns detected; the code performs synchronous output handling with file writes only to user-specified paths, and contains no exfiltration, credential harvesting, obfuscation, or process spawning. |
Show 84 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/io/pipeline.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/strip-newline.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ipc/array.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ipc/buffer-messages.js | safe | The code safely iterates and buffers IPC messages from a subprocess without any malicious patterns such as exfiltration, credential harvesting, or dynamic code execution. |
| lib/ipc/forward.js | safe | No malicious patterns detected; the code only forwards IPC events between processes using standard Node.js APIs. |
| lib/ipc/get-each.js | safe | No malicious patterns detected |
| lib/ipc/get-one.js | safe | No malicious patterns detected; the code is a standard IPC message handler with no exfiltration, obfuscation, or unsafe operations. |
| lib/ipc/graceful.js | safe | No malicious patterns detected; the file implements legitimate Inter-Process Communication (IPC) cancellation handling for the execa library with no exfiltration, credential harvesting, obfuscation, or shell execution. |
| lib/ipc/incoming.js | safe | No malicious patterns detected |
| lib/ipc/ipc-input.js | safe | The code is a straightforward IPC input validation and sending utility with no malicious patterns; it only serializes and sends user-provided input to a subprocess channel. |
| lib/ipc/methods.js | safe | No malicious patterns detected; the code only implements standard Node.js process IPC wrappers without any exfiltration, obfuscation, or suspicious behavior. |
| lib/ipc/outgoing.js | safe | No malicious patterns detected |
| lib/ipc/reference.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ipc/send.js | safe | No malicious patterns detected; the code implements a promise-based IPC send utility with validation, strict response handling, and error management, without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access. |
| lib/ipc/strict.js | safe | No malicious patterns detected |
| lib/ipc/validation.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/bind.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/command.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/create.js | safe | No malicious patterns detected; the code is a legitimate argument-parsing and method-wrapping module for the execa package. |
| lib/methods/main-async.js | safe | No malicious patterns detected; child_process usage is expected for this subprocess execution library and no exfiltration, credential harvesting, obfuscation, or backdoor behavior was found. |
| lib/methods/main-sync.js | safe | No malicious patterns detected |
| lib/methods/node.js | safe | No malicious patterns detected |
| lib/methods/parameters.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/promise.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/script.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/template.js | safe | This code safely parses tagged template strings for the execa library without any malicious patterns such as data exfiltration, environment harvesting, obfuscated code, or unauthorized process execution. |
| lib/pipe/abort.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/pipe/pipe-arguments.js | safe | No malicious patterns detected; the code appears to be legitimate argument normalization for the execa npm package. |
| lib/pipe/sequence.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/pipe/setup.js | safe | No malicious patterns detected |
| lib/pipe/streaming.js | safe | No malicious patterns detected; the code implements standard stream piping with merge-streams and listener management, with no data exfiltration, credential harvesting, obfuscation, network calls, or subprocess spawning. |
| lib/pipe/throw.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/all-async.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/all-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/exit-async.js | safe | No malicious patterns detected; the code is a legitimate subprocess exit-waiting utility using standard Node.js event handling. |
| lib/resolve/exit-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/stdio.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/wait-stream.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/wait-subprocess.js | safe | No malicious patterns detected; the code is a legitimate subprocess result handler with no exfiltration, credential harvesting, obfuscation, or suspicious process/network operations. |
| lib/return/duration.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/early-error.js | safe | No malicious patterns detected; the code handles early subprocess spawn errors by creating dummy streams and an error-wrapping promise without any exfiltration, credential harvesting, obfuscation, or shell execution. |
| lib/return/final-error.js | safe | No malicious patterns detected; the code only defines custom Error classes and a helper to convert subprocess errors, with no network, filesystem, process spawning, or obfuscation behavior. |
| lib/return/message.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/reject.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/result.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/direction.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/duplicate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/handle-async.js | safe | The code is a standard stream handling utility with no malicious patterns, network calls, or suspicious behavior. |
| lib/stdio/handle-sync.js | safe | No malicious patterns detected |
| lib/stdio/handle.js | safe | No malicious patterns detected |
| lib/stdio/input-option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/native.js | safe | No malicious patterns detected |
| lib/stdio/stdio-option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/type.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/terminate/cancel.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/terminate/cleanup.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/terminate/graceful.js | safe | No malicious patterns detected; the file contains legitimate subprocess termination logic with proper validation, error handling, and no network, filesystem, or dynamic code execution risks. |
| lib/terminate/kill-descendants.js | safe | The code safely implements process tree termination on Unix and Windows using standard OS mechanisms without any malicious patterns. |
| lib/terminate/kill.js | safe | No malicious patterns detected |
| lib/terminate/signal.js | safe | No malicious patterns detected; the code only normalizes and validates OS signals using Node.js built-ins and human-signals. |
| lib/terminate/timeout.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/encoding-transform.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/generator.js | safe | No malicious patterns detected |
| lib/transform/normalize.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/object-mode.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/run-async.js | safe | No malicious patterns detected; the code only implements asynchronous transform utilities using Node.js util.callbackify and async generators without any network, filesystem, process, or dynamic execution concerns. |
| lib/transform/run-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/split.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/validate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/abort-signal.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/deferred.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/max-listeners.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/standard-stream.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/uint-array.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/complete.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/custom.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/default.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/info.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/ipc.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/log.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/output.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/start.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/values.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 8.0.1 – 10.0.1 | Needs review | 3 | >=8.0.1 <=10.0.1 | Shell command concatenation without escaping; Process execution library |
| 0.7.0 – 7.2.0 | Not scanned | 4 | >=0.7.0 <=7.2.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of execa
Frequently asked questions
Is execa safe to use?
No confirmed malware was found in execa@10.0.1, but the review flagged 2 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does execa contain malware?
No malware was identified in execa@10.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was execa checked?
Togoder Security downloaded the published npm package and had an AI model read its 109 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan execa together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in execa@10.0.1, cost nothing.