Togoder security

npm package security report

execa@8.0.1 security report

Risky patterns found that deserve a look.

Needs review Version 8.0.1 Files reviewed 9 Size 23.1 KB Scanned

Summary

Togoder Security scanned the npm package execa@8.0.1 on Oct 6, 2026. An AI review of 9 source files produced 4 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
7
low

Findings 11

medium

Process execution library

NPS-517E593C138E

This is the execa library, which is designed to spawn child processes. It uses child_process.spawn and child_process.spawnSync to execute arbitrary commands provided by the caller. While this is the legitimate purpose of the package, the code itself is a process execution primitive that could be misused if the package were compromised or if untrusted input is passed to it.

index.js:70
medium

Command parsing and escaping logic

NPS-C6ECABC13614

The code implements shell command parsing and argument escaping. While it attempts to escape quotes, the logic is simplistic (only escapes double quotes with backslashes) and may be insufficient for safe shell execution, potentially leading to command injection if used with untrusted input. The parseCommand function handles backslash-escaped spaces but does not account for other shell metacharacters.

lib/command.js
medium

Potential for command injection

NPS-EB9FC20D34C8

The escapeArg function uses a naive escaping approach that only wraps arguments containing characters outside [\w.-] in double quotes and escapes embedded double quotes. This does not properly handle all shell special characters (e.g., $, `, \, ;, &, |, etc.) and may not prevent command injection when the resulting command string is passed to a shell.

lib/command.js
medium

File system manipulation outside package scope

NPS-A470BE2C2844

The function pipeToTarget can create a write stream to an arbitrary string path via createWriteStream(target). If a caller passes an attacker-controlled path, this could overwrite or write files outside the package scope (e.g., ~/.ssh/authorized_keys, ~/.bashrc, application configs). While this is a standard API pattern, it represents a potential file-system risk if untrusted input reaches the target argument.

lib/pipe.js:9
low

Environment variable inheritance

NPS-3E42D2820347

By default, extendEnv is true and the child process inherits the full parent process environment via {...process.env, ...envOption}. This is standard for a process-spawning library but means any secrets in the environment (tokens, credentials) are passed to child processes. This is a design choice of the legitimate execa package, not malicious, but worth noting.

index.js:28
low

Local binary resolution

NPS-9B08D723C458

The preferLocal option uses npm-run-path to prepend local node_modules/.bin directories to PATH, allowing execution of locally installed binaries. This is a legitimate feature but could be abused if a malicious package places a binary in node_modules/.bin that shadows a system command.

index.js:30
low

Shell command construction

NPS-EB078B28EAB9

The library constructs command strings via joinCommand and getEscapedCommand for error messages and logging. While it uses cross-spawn's _parse to normalize arguments, the package exposes functions like execaCommand that parse and execute shell-like command strings. This is expected behavior but represents a code execution surface.

index.js:87
low

process termination

NPS-6C48DF0F56A8

The code monkey-patches child process kill behavior and sends SIGTERM/SIGKILL signals. This is expected functionality for a process management library (execa), not a backdoor or reverse shell.

lib/kill.js
low

process spawning (indirect)

NPS-6B817AAA8E9A

The code operates on spawned child processes but does not itself spawn processes via child_process. It provides kill/cancel/timeout/cleanup utilities for child processes created elsewhere.

lib/kill.js
low

Dynamic import / module loading

NPS-725C514E88E7

The module imports from external packages ('node:fs', 'node:child_process', 'is-stream'). 'is-stream' is a third-party dependency; if it were compromised or typosquatted, it could introduce malicious behavior at import time. The imports themselves are static and expected for this library, but dependency trust should be verified.

lib/pipe.js:3
low

Process spawning / pipe to child process

NPS-6ADB7A2128A8

The code accepts an Execa child process as a pipe target and pipes data into its stdin. This is legitimate functionality for a process-management library, but it can be abused to feed attacker-controlled data into another process if the target child process is influenced by untrusted input. No direct shell invocation occurs here, but the capability could contribute to command-execution chains in a larger context.

lib/pipe.js:29

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium This is the legitimate execa package (a well-known child process execution library); no malicious patterns, data exfiltration, obfuscation, or backdoor code were detected, though its inherent purpose is to spawn processes.
lib/command.js medium The code provides command parsing and escaping utilities with incomplete shell escaping that could lead to command injection if misused, but contains no direct malicious patterns such as exfiltration, credential harvesting, or backdoors.
lib/pipe.js medium No overtly malicious patterns such as exfiltration, credential harvesting, or obfuscation were found; however, the code exposes file-write and child-process piping capabilities that could be dangerous if target inputs are attacker-controlled.
lib/error.js safe No malicious patterns detected; the code is a standard error construction utility for the execa process execution library.
lib/kill.js safe The file implements child process termination and timeout utilities (part of the execa package) with no data exfiltration, credential harvesting, obfuscation, or malicious behavior detected.
lib/promise.js safe No malicious patterns detected
lib/stdio.js safe Cleared by Jev triage; no further analysis needed
lib/stream.js safe No malicious patterns detected; the code is a legitimate stream handling utility for child process input/output with no exfiltration, obfuscation, or unauthorized system access.
lib/verbose.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.7.010.0.1
VersionsVerdictCountRangeTop findings
8.0.1 – 10.0.1 Needs review 3 >=8.0.1 <=10.0.1 Shell command concatenation without escaping; Process execution library
0.7.0 – 7.2.0 Not scanned 4 >=0.7.0 <=7.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of execa

VersionVerdictFilesScanned
10.0.1 Needs review 109 Oct 6, 2026
9.6.1 Needs review 106 Oct 6, 2026
8.0.1 Needs review 9 Oct 6, 2026

Frequently asked questions

Is execa safe to use?

No confirmed malware was found in execa@8.0.1, but the review flagged 4 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does execa contain malware?

No malware was identified in execa@8.0.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was execa checked?

Togoder Security downloaded the published npm package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan execa together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in execa@8.0.1, cost nothing.

Related security reports