Summary
Togoder Security scanned the npm package fast-redact@3.5.0 on Oct 4, 2026. An AI review of 17 source files produced 1 high, 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Potential injection through template construction
NPS-8630948E61F5
The redactTmpl function interpolates path, escPath, arrPath, and other path-derived strings directly into the generated code. If an attacker can control the keys of the secret object (e.g., through a prototype pollution or crafted configuration), they could inject malicious JavaScript into the generated function. The code uses JSON.stringify for some values (e.g., arrPath, p in circular detection) but not all; path and escPath are used raw inside template literals that become code. This could lead to code injection if the secret paths are not properly sanitized.
Dynamic code execution via new Function
NPS-99837E6ED55A
The redactor function uses Function('o', ...) to construct a redaction function from a string template. While the input string is built internally from the secret paths and configuration, this pattern is a form of dynamic code generation. If the input to redactor (specifically the secret object keys/paths) can be influenced by untrusted data, it could lead to arbitrary code execution. However, the paths are typically derived from configuration, not direct user input. Nonetheless, the use of new Function is a significant code smell.
Dynamic code execution
NPS-B9B0D2DA392E
The code uses the Function constructor to dynamically create a restore function from a template string. While the inputs are derived from the 'secret' object and paths controlled by the caller, this pattern can be risky if the inputs are not properly sanitized, potentially leading to code injection. However, in this context, it appears to be a deliberate design choice for performance reasons, with internal state binding.
Dynamic code execution
NPS-C554D946A20A
The code uses the Function constructor to dynamically execute a string containing user-provided paths. Although the input is validated against a limited set of characters and patterns, this is a risky pattern that could potentially lead to code injection if the validation is bypassed.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/redactor.js | medium | The code uses new Function to generate redaction logic dynamically, and interpolates secret paths into the generated code without full sanitization, posing a risk of code injection if secret paths are attacker-controlled. |
| lib/restorer.js | medium | The code uses dynamic function generation via the Function constructor, which is a potential security concern if inputs are not strictly controlled, but no immediate malicious patterns like exfiltration or backdoors were found. |
| lib/validator.js | medium | The validator uses dynamic code execution via Function constructor for path validation, which is a risky pattern but appears to have some input sanitization. |
| benchmark/index.js | safe | No malicious patterns detected |
| example/default-usage.js | safe | Cleared by Jev triage; no further analysis needed |
| example/intermediate-wildcard-array.js | safe | Cleared by Jev triage; no further analysis needed |
| example/multi-wildcard-array-depth.js | safe | Cleared by Jev triage; no further analysis needed |
| example/multi-wildcard-array-end.js | safe | Cleared by Jev triage; no further analysis needed |
| example/multi-wildcard-array.js | safe | Cleared by Jev triage; no further analysis needed |
| example/serialize-false.js | safe | Cleared by Jev triage; no further analysis needed |
| example/serialize-function.js | safe | Cleared by Jev triage; no further analysis needed |
| example/top-wildcard-object.js | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | No malicious patterns detected |
| lib/modifiers.js | safe | No malicious patterns detected; the code appears to be a legitimate redaction/restoration utility for pino logging. |
| lib/parse.js | safe | No malicious patterns detected; the file only parses path strings into a structured format using local regex logic. |
| lib/rx.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/state.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is fast-redact safe to use?
No confirmed malware was found in fast-redact@3.5.0, but the review flagged 1 high, 3 medium severity findings for risky patterns worth checking before you rely on it.
Does fast-redact contain malware?
No malware was identified in fast-redact@3.5.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was fast-redact checked?
Togoder Security downloaded the published npm package and had an AI model read its 17 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan fast-redact together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in fast-redact@3.5.0, cost nothing.