Summary
Togoder Security scanned the npm package execa@9.6.1 on Oct 6, 2026. An AI review of 106 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
Shell command concatenation without escaping
NPS-AEA9C3571874
The concatenateShell function joins file and its arguments with spaces into a single shell command string when options.shell is enabled. This replicates Node.js's internal shell concatenation but performs no quoting, escaping, or validation. If any argument originates from untrusted input, it can be interpreted by the shell (command injection, argument injection, or option injection). While the code itself does not exfiltrate data or spawn processes directly, it deliberately constructs shell-parsed command strings, which is a dangerous pattern when callers pass user-controlled values.
Template string parsing (potential shell injection surface)
NPS-D56B64ED43E1
This module parses execa tagged template literals into a file + argument array. Since it splits only on whitespace and performs no shell quoting, the actual safety of command invocation depends on the caller passing the resulting array to a non-shell exec API (e.g., spawn/execFile). If a downstream consumer ever joins these arguments through a shell, user-controlled template expressions could be interpreted as shell syntax.
Environment variable access
NPS-BB96B6DCAF76
While the code passes options to spawn, there is no evidence of harvesting credentials or environment variables for exfiltration. The options are user-provided and used for normal subprocess execution.
Spawning processes
NPS-3E66609AB20E
The code uses child_process.spawn to execute external commands, which is expected behavior for the 'execa' package that provides subprocess execution. The spawned commands come from the arguments passed to the library, not from hardcoded malicious inputs.
Spawning processes
NPS-A6D65B7380F6
The code imports and uses child_process.spawnSync to execute subprocesses. This is expected and legitimate behavior for the execa library, which is designed as a process execution wrapper. No suspicious arguments or data exfiltration are present; spawn is called with parameters derived from caller-supplied options.
Child process reference (not instantiation)
NPS-CC4A3E6A4B89
The file imports ChildProcess from node:child_process, but only uses it for an instanceof check to throw a helpful error when a subprocess is interpolated into a template expression. No process is spawned in this file.
Process termination on exit
NPS-0476CD13A77E
The code registers an onExit handler that calls subprocess.kill() to terminate a child process when the parent process exits. While this is a legitimate cleanup pattern, it involves killing a process, which could be abused if the subprocess reference is controlled or if the cleanup option is enabled unexpectedly. However, the code only runs if the 'cleanup' option is true and the process is not detached, and it is a common pattern in process management libraries.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/arguments/shell.js | medium | The code safely normalizes shell argument handling but performs unescaped string concatenation for shell execution, creating a potential command-injection risk depending on caller-supplied arguments. |
| lib/terminate/cleanup.js | medium | The code implements a cleanup-on-exit handler to kill a subprocess, which is a benign pattern but involves process termination and could be misused in edge cases. |
| index.js | safe | No malicious patterns detected; the file is a standard entry point that re-exports the execa library's public API. |
| lib/arguments/command.js | safe | No malicious patterns detected |
| lib/arguments/cwd.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/encoding-option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/escape.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/fd-options.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/file-url.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/arguments/options.js | safe | No malicious patterns detected |
| lib/arguments/specific.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/add.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/concurrent.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/duplex.js | safe | No malicious patterns detected; the code creates a Duplex stream wrapper around a subprocess without any network, filesystem, or code execution concerns. |
| lib/convert/iterable.js | safe | No malicious patterns detected; the code is a straightforward async iterable converter for subprocess stdout streams. |
| lib/convert/readable.js | safe | No malicious patterns detected; code implements a readable stream wrapper for subprocess stdout with no exfiltration, obfuscation, credential access, or network activity. |
| lib/convert/shared.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/convert/writable.js | safe | No malicious patterns detected in this stream-wrapping utility module. |
| lib/io/contents.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/input-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/iterate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/max-buffer.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/output-async.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/io/output-sync.js | safe | The code performs synchronous output transformation and file writing for stdout/stderr handling without any malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| lib/io/pipeline.js | safe | Cleared by Jev triage; no further analysis needed |
Show 81 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/io/strip-newline.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ipc/array.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ipc/buffer-messages.js | safe | The code safely iterates and buffers IPC messages from a subprocess without any malicious patterns such as exfiltration, credential harvesting, or dynamic code execution. |
| lib/ipc/forward.js | safe | No malicious patterns detected |
| lib/ipc/get-each.js | safe | No malicious patterns detected |
| lib/ipc/get-one.js | safe | No malicious patterns detected; the code is a legitimate IPC message-handling utility for subprocess communication. |
| lib/ipc/graceful.js | safe | The code implements IPC-based graceful cancellation for subprocesses using standard Node.js APIs with no malicious patterns detected. |
| lib/ipc/incoming.js | safe | No malicious patterns detected |
| lib/ipc/ipc-input.js | safe | No malicious patterns detected; the code only validates and forwards an IPC input option using standard serialization checks. |
| lib/ipc/methods.js | safe | No malicious patterns detected; the code implements standard Node.js IPC helper methods without exfiltration, credential harvesting, obfuscation, or other red flags. |
| lib/ipc/outgoing.js | safe | No malicious patterns detected; the code implements internal IPC message synchronization for a subprocess library without network, filesystem, credential, or dynamic execution concerns. |
| lib/ipc/reference.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ipc/send.js | safe | No malicious patterns detected; the code implements a promise-based IPC send utility with validation, strict response handling, and error management, without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access. |
| lib/ipc/strict.js | safe | No malicious patterns detected |
| lib/ipc/validation.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/bind.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/command.js | safe | No malicious patterns detected |
| lib/methods/create.js | safe | No malicious patterns detected; the code is a legitimate argument parsing and execution wrapper for the execa library. |
| lib/methods/main-async.js | safe | The code is part of the legitimate 'execa' npm package and contains standard subprocess execution logic without any malicious patterns. |
| lib/methods/main-sync.js | safe | No malicious patterns detected; child_process usage is the intended core functionality of the execa package. |
| lib/methods/node.js | safe | No malicious patterns detected; the code is a legitimate utility module for the execa package that handles Node.js execution options without any exfiltration, credential harvesting, or obfuscation. |
| lib/methods/parameters.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/promise.js | safe | No malicious patterns detected; code only mixes Promise methods into a subprocess object using standard reflection. |
| lib/methods/script.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/methods/template.js | safe | The file only parses execa tagged template strings into command/argument arrays and performs type checks; no exfiltration, credential harvesting, dynamic evaluation, process spawning, or filesystem manipulation is present, though callers must ensure the resulting argument array is never passed through a shell. |
| lib/pipe/abort.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/pipe/pipe-arguments.js | safe | No malicious patterns detected; the code appears to be legitimate argument normalization for the execa npm package. |
| lib/pipe/sequence.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/pipe/setup.js | safe | The code is part of a subprocess piping library and contains no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| lib/pipe/streaming.js | safe | No malicious patterns detected; the code implements standard stream piping with merge-streams and listener management, with no data exfiltration, credential harvesting, obfuscation, network calls, or subprocess spawning. |
| lib/pipe/throw.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/all-async.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/all-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/exit-async.js | safe | No malicious patterns detected; the code is a legitimate subprocess exit-waiting utility using standard Node.js event handling. |
| lib/resolve/exit-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/stdio.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/wait-stream.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/resolve/wait-subprocess.js | safe | This file is part of a subprocess management utility (resembling execa) and contains no malicious patterns; it handles process lifecycle, stream waiting, timeouts, and IPC without exfiltration, credential harvesting, obfuscation, or other red flags. |
| lib/return/duration.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/early-error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/final-error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/message.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/reject.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/return/result.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/direction.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/duplicate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/handle-async.js | safe | The code is a standard stream handling utility with no malicious patterns, network calls, or suspicious behavior. |
| lib/stdio/handle-sync.js | safe | No malicious patterns detected; the code synchronously handles stdio options for process spawning with no exfiltration, obfuscation, or unauthorized file/network/process operations. |
| lib/stdio/handle.js | safe | No malicious patterns detected; the code is a legitimate stdio option handling module from the Execa library with no exfiltration, credential harvesting, obfuscation, or command execution. |
| lib/stdio/input-option.js | safe | No malicious patterns detected; this is a benign input validation and normalization module for stdio options. |
| lib/stdio/native.js | safe | No malicious patterns detected |
| lib/stdio/stdio-option.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stdio/type.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/terminate/cancel.js | safe | No malicious patterns detected |
| lib/terminate/graceful.js | safe | This file implements graceful subprocess termination logic using AbortSignal and IPC, with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file/process operations. |
| lib/terminate/kill.js | safe | No malicious patterns detected |
| lib/terminate/signal.js | safe | No malicious patterns detected; the code only normalizes and validates OS signals using Node.js built-ins and human-signals. |
| lib/terminate/timeout.js | safe | No malicious patterns detected; the code is a legitimate timeout utility for subprocess termination. |
| lib/transform/encoding-transform.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/generator.js | safe | No malicious patterns detected |
| lib/transform/normalize.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/object-mode.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/run-async.js | safe | No malicious patterns detected; the code only implements asynchronous transform utilities using Node.js util.callbackify and async generators without any network, filesystem, process, or dynamic execution concerns. |
| lib/transform/run-sync.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/split.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/transform/validate.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/abort-signal.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/deferred.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/max-listeners.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/standard-stream.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils/uint-array.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/complete.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/custom.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/default.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/info.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/ipc.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/log.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/output.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/start.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/verbose/values.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 8.0.1 – 10.0.1 | Needs review | 3 | >=8.0.1 <=10.0.1 | Shell command concatenation without escaping; Process execution library |
| 0.7.0 – 7.2.0 | Not scanned | 4 | >=0.7.0 <=7.2.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of execa
Frequently asked questions
Is execa safe to use?
No confirmed malware was found in execa@9.6.1, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does execa contain malware?
No malware was identified in execa@9.6.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was execa checked?
Togoder Security downloaded the published npm package and had an AI model read its 106 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan execa together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in execa@9.6.1, cost nothing.