Togoder security

npm package security report

fast-redact@3.5.0 security report

Risky patterns found that deserve a look.

Needs review Version 3.5.0 Files reviewed 17 Size 28.9 KB Scanned

Summary

Togoder Security scanned the npm package fast-redact@3.5.0 on Oct 4, 2026. An AI review of 17 source files produced 1 high, 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
3
medium
0
low

Findings 4

high

Potential injection through template construction

NPS-8630948E61F5

The redactTmpl function interpolates path, escPath, arrPath, and other path-derived strings directly into the generated code. If an attacker can control the keys of the secret object (e.g., through a prototype pollution or crafted configuration), they could inject malicious JavaScript into the generated function. The code uses JSON.stringify for some values (e.g., arrPath, p in circular detection) but not all; path and escPath are used raw inside template literals that become code. This could lead to code injection if the secret paths are not properly sanitized.

lib/redactor.js:28
medium

Dynamic code execution via new Function

NPS-99837E6ED55A

The redactor function uses Function('o', ...) to construct a redaction function from a string template. While the input string is built internally from the secret paths and configuration, this pattern is a form of dynamic code generation. If the input to redactor (specifically the secret object keys/paths) can be influenced by untrusted data, it could lead to arbitrary code execution. However, the paths are typically derived from configuration, not direct user input. Nonetheless, the use of new Function is a significant code smell.

lib/redactor.js:6
medium

Dynamic code execution

NPS-B9B0D2DA392E

The code uses the Function constructor to dynamically create a restore function from a template string. While the inputs are derived from the 'secret' object and paths controlled by the caller, this pattern can be risky if the inputs are not properly sanitized, potentially leading to code injection. However, in this context, it appears to be a deliberate design choice for performance reasons, with internal state binding.

lib/restorer.js:18
medium

Dynamic code execution

NPS-C554D946A20A

The code uses the Function constructor to dynamically execute a string containing user-provided paths. Although the input is validated against a limited set of characters and patterns, this is a risky pattern that could potentially lead to code injection if the validation is bypassed.

lib/validator.js:23

Files reviewed

FileVerdictWhat the reviewer saw
lib/redactor.js medium The code uses new Function to generate redaction logic dynamically, and interpolates secret paths into the generated code without full sanitization, posing a risk of code injection if secret paths are attacker-controlled.
lib/restorer.js medium The code uses dynamic function generation via the Function constructor, which is a potential security concern if inputs are not strictly controlled, but no immediate malicious patterns like exfiltration or backdoors were found.
lib/validator.js medium The validator uses dynamic code execution via Function constructor for path validation, which is a risky pattern but appears to have some input sanitization.
benchmark/index.js safe No malicious patterns detected
example/default-usage.js safe Cleared by Jev triage; no further analysis needed
example/intermediate-wildcard-array.js safe Cleared by Jev triage; no further analysis needed
example/multi-wildcard-array-depth.js safe Cleared by Jev triage; no further analysis needed
example/multi-wildcard-array-end.js safe Cleared by Jev triage; no further analysis needed
example/multi-wildcard-array.js safe Cleared by Jev triage; no further analysis needed
example/serialize-false.js safe Cleared by Jev triage; no further analysis needed
example/serialize-function.js safe Cleared by Jev triage; no further analysis needed
example/top-wildcard-object.js safe Cleared by Jev triage; no further analysis needed
index.js safe No malicious patterns detected
lib/modifiers.js safe No malicious patterns detected; the code appears to be a legitimate redaction/restoration utility for pino logging.
lib/parse.js safe No malicious patterns detected; the file only parses path strings into a structured format using local regex logic.
lib/rx.js safe Cleared by Jev triage; no further analysis needed
lib/state.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is fast-redact safe to use?

No confirmed malware was found in fast-redact@3.5.0, but the review flagged 1 high, 3 medium severity findings for risky patterns worth checking before you rely on it.

Does fast-redact contain malware?

No malware was identified in fast-redact@3.5.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was fast-redact checked?

Togoder Security downloaded the published npm package and had an AI model read its 17 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan fast-redact together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in fast-redact@3.5.0, cost nothing.

Related security reports