Togoder security

npm package security report

execa@9.6.1 security report

Risky patterns found that deserve a look.

Needs review Version 9.6.1 Files reviewed 106 Size 220.4 KB Scanned

Summary

Togoder Security scanned the npm package execa@9.6.1 on Oct 6, 2026. An AI review of 106 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
5
low

Findings 7

medium

Shell command concatenation without escaping

NPS-AEA9C3571874

The concatenateShell function joins file and its arguments with spaces into a single shell command string when options.shell is enabled. This replicates Node.js's internal shell concatenation but performs no quoting, escaping, or validation. If any argument originates from untrusted input, it can be interpreted by the shell (command injection, argument injection, or option injection). While the code itself does not exfiltrate data or spawn processes directly, it deliberately constructs shell-parsed command strings, which is a dangerous pattern when callers pass user-controlled values.

lib/arguments/shell.js:9
medium

Template string parsing (potential shell injection surface)

NPS-D56B64ED43E1

This module parses execa tagged template literals into a file + argument array. Since it splits only on whitespace and performs no shell quoting, the actual safety of command invocation depends on the caller passing the resulting array to a non-shell exec API (e.g., spawn/execFile). If a downstream consumer ever joins these arguments through a shell, user-controlled template expressions could be interpreted as shell syntax.

lib/methods/template.js:8
low

Environment variable access

NPS-BB96B6DCAF76

While the code passes options to spawn, there is no evidence of harvesting credentials or environment variables for exfiltration. The options are user-provided and used for normal subprocess execution.

lib/methods/main-async.js
low

Spawning processes

NPS-3E66609AB20E

The code uses child_process.spawn to execute external commands, which is expected behavior for the 'execa' package that provides subprocess execution. The spawned commands come from the arguments passed to the library, not from hardcoded malicious inputs.

lib/methods/main-async.js:57
low

Spawning processes

NPS-A6D65B7380F6

The code imports and uses child_process.spawnSync to execute subprocesses. This is expected and legitimate behavior for the execa library, which is designed as a process execution wrapper. No suspicious arguments or data exfiltration are present; spawn is called with parameters derived from caller-supplied options.

lib/methods/main-sync.js:1
low

Child process reference (not instantiation)

NPS-CC4A3E6A4B89

The file imports ChildProcess from node:child_process, but only uses it for an instanceof check to throw a helpful error when a subprocess is interpolated into a template expression. No process is spawned in this file.

lib/methods/template.js:1
low

Process termination on exit

NPS-0476CD13A77E

The code registers an onExit handler that calls subprocess.kill() to terminate a child process when the parent process exits. While this is a legitimate cleanup pattern, it involves killing a process, which could be abused if the subprocess reference is controlled or if the cleanup option is enabled unexpectedly. However, the code only runs if the 'cleanup' option is true and the process is not detached, and it is a common pattern in process management libraries.

lib/terminate/cleanup.js:9

Files reviewed

FileVerdictWhat the reviewer saw
lib/arguments/shell.js medium The code safely normalizes shell argument handling but performs unescaped string concatenation for shell execution, creating a potential command-injection risk depending on caller-supplied arguments.
lib/terminate/cleanup.js medium The code implements a cleanup-on-exit handler to kill a subprocess, which is a benign pattern but involves process termination and could be misused in edge cases.
index.js safe No malicious patterns detected; the file is a standard entry point that re-exports the execa library's public API.
lib/arguments/command.js safe No malicious patterns detected
lib/arguments/cwd.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/encoding-option.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/escape.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/fd-options.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/file-url.js safe Cleared by Jev triage; no further analysis needed
lib/arguments/options.js safe No malicious patterns detected
lib/arguments/specific.js safe Cleared by Jev triage; no further analysis needed
lib/convert/add.js safe Cleared by Jev triage; no further analysis needed
lib/convert/concurrent.js safe Cleared by Jev triage; no further analysis needed
lib/convert/duplex.js safe No malicious patterns detected; the code creates a Duplex stream wrapper around a subprocess without any network, filesystem, or code execution concerns.
lib/convert/iterable.js safe No malicious patterns detected; the code is a straightforward async iterable converter for subprocess stdout streams.
lib/convert/readable.js safe No malicious patterns detected; code implements a readable stream wrapper for subprocess stdout with no exfiltration, obfuscation, credential access, or network activity.
lib/convert/shared.js safe Cleared by Jev triage; no further analysis needed
lib/convert/writable.js safe No malicious patterns detected in this stream-wrapping utility module.
lib/io/contents.js safe Cleared by Jev triage; no further analysis needed
lib/io/input-sync.js safe Cleared by Jev triage; no further analysis needed
lib/io/iterate.js safe Cleared by Jev triage; no further analysis needed
lib/io/max-buffer.js safe Cleared by Jev triage; no further analysis needed
lib/io/output-async.js safe Cleared by Jev triage; no further analysis needed
lib/io/output-sync.js safe The code performs synchronous output transformation and file writing for stdout/stderr handling without any malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
lib/io/pipeline.js safe Cleared by Jev triage; no further analysis needed
Show 81 more files
FileVerdictWhat the reviewer saw
lib/io/strip-newline.js safe Cleared by Jev triage; no further analysis needed
lib/ipc/array.js safe Cleared by Jev triage; no further analysis needed
lib/ipc/buffer-messages.js safe The code safely iterates and buffers IPC messages from a subprocess without any malicious patterns such as exfiltration, credential harvesting, or dynamic code execution.
lib/ipc/forward.js safe No malicious patterns detected
lib/ipc/get-each.js safe No malicious patterns detected
lib/ipc/get-one.js safe No malicious patterns detected; the code is a legitimate IPC message-handling utility for subprocess communication.
lib/ipc/graceful.js safe The code implements IPC-based graceful cancellation for subprocesses using standard Node.js APIs with no malicious patterns detected.
lib/ipc/incoming.js safe No malicious patterns detected
lib/ipc/ipc-input.js safe No malicious patterns detected; the code only validates and forwards an IPC input option using standard serialization checks.
lib/ipc/methods.js safe No malicious patterns detected; the code implements standard Node.js IPC helper methods without exfiltration, credential harvesting, obfuscation, or other red flags.
lib/ipc/outgoing.js safe No malicious patterns detected; the code implements internal IPC message synchronization for a subprocess library without network, filesystem, credential, or dynamic execution concerns.
lib/ipc/reference.js safe Cleared by Jev triage; no further analysis needed
lib/ipc/send.js safe No malicious patterns detected; the code implements a promise-based IPC send utility with validation, strict response handling, and error management, without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
lib/ipc/strict.js safe No malicious patterns detected
lib/ipc/validation.js safe Cleared by Jev triage; no further analysis needed
lib/methods/bind.js safe Cleared by Jev triage; no further analysis needed
lib/methods/command.js safe No malicious patterns detected
lib/methods/create.js safe No malicious patterns detected; the code is a legitimate argument parsing and execution wrapper for the execa library.
lib/methods/main-async.js safe The code is part of the legitimate 'execa' npm package and contains standard subprocess execution logic without any malicious patterns.
lib/methods/main-sync.js safe No malicious patterns detected; child_process usage is the intended core functionality of the execa package.
lib/methods/node.js safe No malicious patterns detected; the code is a legitimate utility module for the execa package that handles Node.js execution options without any exfiltration, credential harvesting, or obfuscation.
lib/methods/parameters.js safe Cleared by Jev triage; no further analysis needed
lib/methods/promise.js safe No malicious patterns detected; code only mixes Promise methods into a subprocess object using standard reflection.
lib/methods/script.js safe Cleared by Jev triage; no further analysis needed
lib/methods/template.js safe The file only parses execa tagged template strings into command/argument arrays and performs type checks; no exfiltration, credential harvesting, dynamic evaluation, process spawning, or filesystem manipulation is present, though callers must ensure the resulting argument array is never passed through a shell.
lib/pipe/abort.js safe Cleared by Jev triage; no further analysis needed
lib/pipe/pipe-arguments.js safe No malicious patterns detected; the code appears to be legitimate argument normalization for the execa npm package.
lib/pipe/sequence.js safe Cleared by Jev triage; no further analysis needed
lib/pipe/setup.js safe The code is part of a subprocess piping library and contains no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
lib/pipe/streaming.js safe No malicious patterns detected; the code implements standard stream piping with merge-streams and listener management, with no data exfiltration, credential harvesting, obfuscation, network calls, or subprocess spawning.
lib/pipe/throw.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/all-async.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/all-sync.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/exit-async.js safe No malicious patterns detected; the code is a legitimate subprocess exit-waiting utility using standard Node.js event handling.
lib/resolve/exit-sync.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/stdio.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/wait-stream.js safe Cleared by Jev triage; no further analysis needed
lib/resolve/wait-subprocess.js safe This file is part of a subprocess management utility (resembling execa) and contains no malicious patterns; it handles process lifecycle, stream waiting, timeouts, and IPC without exfiltration, credential harvesting, obfuscation, or other red flags.
lib/return/duration.js safe Cleared by Jev triage; no further analysis needed
lib/return/early-error.js safe Cleared by Jev triage; no further analysis needed
lib/return/final-error.js safe Cleared by Jev triage; no further analysis needed
lib/return/message.js safe Cleared by Jev triage; no further analysis needed
lib/return/reject.js safe Cleared by Jev triage; no further analysis needed
lib/return/result.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/direction.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/duplicate.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/handle-async.js safe The code is a standard stream handling utility with no malicious patterns, network calls, or suspicious behavior.
lib/stdio/handle-sync.js safe No malicious patterns detected; the code synchronously handles stdio options for process spawning with no exfiltration, obfuscation, or unauthorized file/network/process operations.
lib/stdio/handle.js safe No malicious patterns detected; the code is a legitimate stdio option handling module from the Execa library with no exfiltration, credential harvesting, obfuscation, or command execution.
lib/stdio/input-option.js safe No malicious patterns detected; this is a benign input validation and normalization module for stdio options.
lib/stdio/native.js safe No malicious patterns detected
lib/stdio/stdio-option.js safe Cleared by Jev triage; no further analysis needed
lib/stdio/type.js safe Cleared by Jev triage; no further analysis needed
lib/terminate/cancel.js safe No malicious patterns detected
lib/terminate/graceful.js safe This file implements graceful subprocess termination logic using AbortSignal and IPC, with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file/process operations.
lib/terminate/kill.js safe No malicious patterns detected
lib/terminate/signal.js safe No malicious patterns detected; the code only normalizes and validates OS signals using Node.js built-ins and human-signals.
lib/terminate/timeout.js safe No malicious patterns detected; the code is a legitimate timeout utility for subprocess termination.
lib/transform/encoding-transform.js safe Cleared by Jev triage; no further analysis needed
lib/transform/generator.js safe No malicious patterns detected
lib/transform/normalize.js safe Cleared by Jev triage; no further analysis needed
lib/transform/object-mode.js safe Cleared by Jev triage; no further analysis needed
lib/transform/run-async.js safe No malicious patterns detected; the code only implements asynchronous transform utilities using Node.js util.callbackify and async generators without any network, filesystem, process, or dynamic execution concerns.
lib/transform/run-sync.js safe Cleared by Jev triage; no further analysis needed
lib/transform/split.js safe Cleared by Jev triage; no further analysis needed
lib/transform/validate.js safe Cleared by Jev triage; no further analysis needed
lib/utils/abort-signal.js safe Cleared by Jev triage; no further analysis needed
lib/utils/deferred.js safe Cleared by Jev triage; no further analysis needed
lib/utils/max-listeners.js safe Cleared by Jev triage; no further analysis needed
lib/utils/standard-stream.js safe Cleared by Jev triage; no further analysis needed
lib/utils/uint-array.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/complete.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/custom.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/default.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/error.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/info.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/ipc.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/log.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/output.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/start.js safe Cleared by Jev triage; no further analysis needed
lib/verbose/values.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 3 scanned versions of execa are flagged high or critical. The latest scanned version, 10.0.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.7.010.0.1
VersionsVerdictCountRangeTop findings
8.0.1 – 10.0.1 Needs review 3 >=8.0.1 <=10.0.1 Shell command concatenation without escaping; Process execution library
0.7.0 – 7.2.0 Not scanned 4 >=0.7.0 <=7.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of execa

VersionVerdictFilesScanned
10.0.1 Needs review 109 Oct 6, 2026
9.6.1 Needs review 106 Oct 6, 2026
8.0.1 Needs review 9 Oct 6, 2026

Frequently asked questions

Is execa safe to use?

No confirmed malware was found in execa@9.6.1, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does execa contain malware?

No malware was identified in execa@9.6.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was execa checked?

Togoder Security downloaded the published npm package and had an AI model read its 106 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan execa together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in execa@9.6.1, cost nothing.

Related security reports