Togoder security

npm package security report

execa@10.0.1 security report

Risky patterns found that deserve a look.

Needs review Version 10.0.1 Files reviewed 109 Size 246.8 KB Scanned

Summary

Togoder Security scanned the npm package execa@10.0.1 on Oct 6, 2026. An AI review of 109 source files produced 2 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
7
low

Findings 9

medium

Spawning processes or shell commands

NPS-5E4A35DD28C8

The code constructs and executes Windows command lines via cmd.exe with 'windowsVerbatimArguments' enabled and manual escaping logic. While the escaping appears intentional and defensive (rejecting CR/LF, caret-escaping metacharacters), this pattern is inherently high-risk and could enable command injection if any escaping edge case is missed or if an attacker can influence the file path or arguments.

lib/arguments/command-file.js
medium

Shell command concatenation without escaping

NPS-AEA9C3571874

The concatenateShell function joins file and its arguments with spaces into a single shell command string when options.shell is enabled. This replicates Node.js's internal shell concatenation but performs no quoting, escaping, or validation. If any argument originates from untrusted input, it can be interpreted by the shell (command injection, argument injection, or option injection). While the code itself does not exfiltrate data or spawn processes directly, it deliberately constructs shell-parsed command strings, which is a dangerous pattern when callers pass user-controlled values.

lib/arguments/shell.js:9
low

File system read outside package scope

NPS-5F0CFD34FFB0

readShebang opens and reads the first 150 bytes of arbitrary resolved files to parse shebang interpreters. This is expected for command resolution but does involve reading files outside the package boundary.

lib/arguments/command-file.js
low

Environment variable harvesting

NPS-616BE54A33D8

The code reads PATH, PATHEXT, comspec, and NODEFAULTCURRENTDIRECTORYINEXEPATH environment variables. These are standard for Windows command resolution and are not credential-related, but environment access is present.

lib/arguments/command-file.js
low

Dynamic path resolution using external inputs

NPS-D2EBF067A10D

whichCommandSync is used with user-supplied file/command names to resolve executables from PATH/PATHEXT. This can cause execution of unexpected binaries if the environment is attacker-controlled, though it is standard behavior for command launchers.

lib/arguments/command-file.js
low

Process spawning

NPS-1602732130CC

Uses child_process.spawn to execute subprocesses, but this is the core purpose of the execa library and arguments are normalized through internal handlers; no unsanitized user input or external dynamic commands are present.

lib/methods/main-async.js:90
low

ChildProcess import

NPS-05FEAE71C8C2

The file imports ChildProcess from 'node:child_process', but only uses it for type checking (instanceof) to validate template expressions, not for executing commands.

lib/methods/template.js:1
low

Process Spawning

NPS-AFAF96020C3B

The code uses child_process.execFile to spawn taskkill.exe on Windows for terminating process trees. This is a legitimate use case for process termination and not a malicious pattern. The executable path is derived from environment variables (SystemRoot/windir) and validated to be a Windows drive absolute path before joining with System32\taskkill.exe.

lib/terminate/kill-descendants.js:60
low

Environment Variable Usage

NPS-9986573E60F7

Reads SystemRoot and windir environment variables to locate taskkill.exe on Windows. This is standard practice for locating system executables and does not constitute credential harvesting.

lib/terminate/kill-descendants.js:74

Files reviewed

FileVerdictWhat the reviewer saw
lib/arguments/command-file.js medium The file implements Windows command-line escaping and resolution for a well-known package (execa); it contains no exfiltration, credential theft, obfuscation, or backdoor patterns, but does spawn cmd.exe and read environment/filesystem paths in ways that warrant a warning-level review.
lib/arguments/shell.js medium The code safely normalizes shell argument handling but performs unescaped string concatenation for shell execution, creating a potential command-injection risk depending on caller-supplied arguments.
index.js safe This is the public entry point for the execa package, containing only standard imports/exports with no malicious patterns, obfuscation, or suspicious behavior.
lib/arguments/command.js safe No malicious patterns detected
lib/arguments/cwd.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/encoding-option.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/escape.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/fd-options.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/file-url.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/options.js safe No malicious patterns detected; the code performs standard option normalization for a child process library with explicit prototype pollution protections.
lib/arguments/specific.js safe Cleared by Jev triage; no further analysis needed
lib/convert/add.js safe Cleared by Jev triage; no further analysis needed
lib/convert/concurrent.js safe Cleared by Jev triage; no further analysis needed
lib/convert/duplex.js safe No malicious patterns detected; the code only constructs a Node.js Duplex stream wrapper around a subprocess with no external network, filesystem, or process-spawning behavior.
lib/convert/iterable.js safe No malicious patterns detected; the code is a straightforward async iterable converter for subprocess stdout streams.
lib/convert/readable.js safe No malicious patterns detected
lib/convert/shared.js safe Cleared by Jev triage; no further analysis needed
lib/convert/web.js safe Cleared by Jev triage; no further analysis needed
lib/convert/writable.js safe No malicious patterns detected in the writable stream conversion module; it only handles subprocess I/O forwarding without any suspicious behavior.
lib/io/contents.js safe Cleared by Jev triage; no further analysis needed
lib/io/input-sync.js safe Cleared by Jev triage; no further analysis needed
lib/io/iterate.js safe Cleared by Jev triage; no further analysis needed
lib/io/max-buffer.js safe Cleared by Jev triage; no further analysis needed
lib/io/output-async.js safe No malicious patterns detected; the module only handles stream piping for subprocess I/O with no external network, credential, or code execution activities.
lib/io/output-sync.js safe No malicious patterns detected; the code performs synchronous output handling with file writes only to user-specified paths, and contains no exfiltration, credential harvesting, obfuscation, or process spawning.
Show 84 more files
FileVerdictWhat the reviewer saw
lib/io/pipeline.js safe Cleared by Jev triage; no further analysis needed
lib/io/strip-newline.js safe Cleared by Jev triage; no further analysis needed
lib/ipc/array.js safe Cleared by Jev triage; no further analysis needed
lib/ipc/buffer-messages.js safe The code safely iterates and buffers IPC messages from a subprocess without any malicious patterns such as exfiltration, credential harvesting, or dynamic code execution.
lib/ipc/forward.js safe No malicious patterns detected; the code only forwards IPC events between processes using standard Node.js APIs.
lib/ipc/get-each.js safe No malicious patterns detected
lib/ipc/get-one.js safe No malicious patterns detected; the code is a standard IPC message handler with no exfiltration, obfuscation, or unsafe operations.
lib/ipc/graceful.js safe No malicious patterns detected; the file implements legitimate Inter-Process Communication (IPC) cancellation handling for the execa library with no exfiltration, credential harvesting, obfuscation, or shell execution.
lib/ipc/incoming.js safe No malicious patterns detected
lib/ipc/ipc-input.js safe The code is a straightforward IPC input validation and sending utility with no malicious patterns; it only serializes and sends user-provided input to a subprocess channel.
lib/ipc/methods.js safe No malicious patterns detected; the code only implements standard Node.js process IPC wrappers without any exfiltration, obfuscation, or suspicious behavior.
lib/ipc/outgoing.js safe No malicious patterns detected
lib/ipc/reference.js safe Cleared by Jev triage; no further analysis needed
lib/ipc/send.js safe No malicious patterns detected; the code implements a promise-based IPC send utility with validation, strict response handling, and error management, without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
lib/ipc/strict.js safe No malicious patterns detected
lib/ipc/validation.js safe Cleared by Jev triage; no further analysis needed
lib/methods/bind.js safe Cleared by Jev triage; no further analysis needed
lib/methods/command.js safe Cleared by Jev triage; no further analysis needed
lib/methods/create.js safe No malicious patterns detected; the code is a legitimate argument-parsing and method-wrapping module for the execa package.
lib/methods/main-async.js safe No malicious patterns detected; child_process usage is expected for this subprocess execution library and no exfiltration, credential harvesting, obfuscation, or backdoor behavior was found.
lib/methods/main-sync.js safe No malicious patterns detected
lib/methods/node.js safe No malicious patterns detected
lib/methods/parameters.js safe Cleared by Jev triage; no further analysis needed
lib/methods/promise.js safe Cleared by Jev triage; no further analysis needed
lib/methods/script.js safe Cleared by Jev triage; no further analysis needed
lib/methods/template.js safe This code safely parses tagged template strings for the execa library without any malicious patterns such as data exfiltration, environment harvesting, obfuscated code, or unauthorized process execution.
lib/pipe/abort.js safe Cleared by Jev triage; no further analysis needed
lib/pipe/pipe-arguments.js safe No malicious patterns detected; the code appears to be legitimate argument normalization for the execa npm package.
lib/pipe/sequence.js safe Cleared by Jev triage; no further analysis needed
lib/pipe/setup.js safe No malicious patterns detected
lib/pipe/streaming.js safe No malicious patterns detected; the code implements standard stream piping with merge-streams and listener management, with no data exfiltration, credential harvesting, obfuscation, network calls, or subprocess spawning.
lib/pipe/throw.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/all-async.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/all-sync.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/exit-async.js safe No malicious patterns detected; the code is a legitimate subprocess exit-waiting utility using standard Node.js event handling.
lib/resolve/exit-sync.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/stdio.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/wait-stream.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/wait-subprocess.js safe No malicious patterns detected; the code is a legitimate subprocess result handler with no exfiltration, credential harvesting, obfuscation, or suspicious process/network operations.
lib/return/duration.js safe Cleared by Jev triage; no further analysis needed
lib/return/early-error.js safe No malicious patterns detected; the code handles early subprocess spawn errors by creating dummy streams and an error-wrapping promise without any exfiltration, credential harvesting, obfuscation, or shell execution.
lib/return/final-error.js safe No malicious patterns detected; the code only defines custom Error classes and a helper to convert subprocess errors, with no network, filesystem, process spawning, or obfuscation behavior.
lib/return/message.js safe Cleared by Jev triage; no further analysis needed
lib/return/reject.js safe Cleared by Jev triage; no further analysis needed
lib/return/result.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/direction.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/duplicate.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/handle-async.js safe The code is a standard stream handling utility with no malicious patterns, network calls, or suspicious behavior.
lib/stdio/handle-sync.js safe No malicious patterns detected
lib/stdio/handle.js safe No malicious patterns detected
lib/stdio/input-option.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/native.js safe No malicious patterns detected
lib/stdio/stdio-option.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/type.js safe Cleared by Jev triage; no further analysis needed
lib/terminate/cancel.js safe Cleared by Jev triage; no further analysis needed
lib/terminate/cleanup.js safe Cleared by Jev triage; no further analysis needed
lib/terminate/graceful.js safe No malicious patterns detected; the file contains legitimate subprocess termination logic with proper validation, error handling, and no network, filesystem, or dynamic code execution risks.
lib/terminate/kill-descendants.js safe The code safely implements process tree termination on Unix and Windows using standard OS mechanisms without any malicious patterns.
lib/terminate/kill.js safe No malicious patterns detected
lib/terminate/signal.js safe No malicious patterns detected; the code only normalizes and validates OS signals using Node.js built-ins and human-signals.
lib/terminate/timeout.js safe Cleared by Jev triage; no further analysis needed
lib/transform/encoding-transform.js safe Cleared by Jev triage; no further analysis needed
lib/transform/generator.js safe No malicious patterns detected
lib/transform/normalize.js safe Cleared by Jev triage; no further analysis needed
lib/transform/object-mode.js safe Cleared by Jev triage; no further analysis needed
lib/transform/run-async.js safe No malicious patterns detected; the code only implements asynchronous transform utilities using Node.js util.callbackify and async generators without any network, filesystem, process, or dynamic execution concerns.
lib/transform/run-sync.js safe Cleared by Jev triage; no further analysis needed
lib/transform/split.js safe Cleared by Jev triage; no further analysis needed
lib/transform/validate.js safe Cleared by Jev triage; no further analysis needed
lib/utils/abort-signal.js safe Cleared by Jev triage; no further analysis needed
lib/utils/deferred.js safe Cleared by Jev triage; no further analysis needed
lib/utils/max-listeners.js safe Cleared by Jev triage; no further analysis needed
lib/utils/standard-stream.js safe Cleared by Jev triage; no further analysis needed
lib/utils/uint-array.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/complete.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/custom.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/default.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/error.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/info.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/ipc.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/log.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/output.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/start.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/values.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.7.010.0.1
VersionsVerdictCountRangeTop findings
8.0.1 – 10.0.1 Needs review 3 >=8.0.1 <=10.0.1 Shell command concatenation without escaping; Process execution library
0.7.0 – 7.2.0 Not scanned 4 >=0.7.0 <=7.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of execa

VersionVerdictFilesScanned
10.0.1 Needs review 109 Oct 6, 2026
9.6.1 Needs review 106 Oct 6, 2026
8.0.1 Needs review 9 Oct 6, 2026

Frequently asked questions

Is execa safe to use?

No confirmed malware was found in execa@10.0.1, but the review flagged 2 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does execa contain malware?

No malware was identified in execa@10.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was execa checked?

Togoder Security downloaded the published npm package and had an AI model read its 109 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan execa together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in execa@10.0.1, cost nothing.

Related security reports