Togoder security

npm package security report

fast-stable-stringify npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.0.0 Files reviewed 13 Size 20.0 KB Scanned

Summary

Togoder Security scanned the npm package fast-stable-stringify@1.0.0 on Oct 4, 2026. An AI review of 13 source files produced 2 high, 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
2
high
1
medium
2
low

Findings 5

high

Command injection via shell execSync

NPS-D226154C91AB

The function passes its filePath parameter directly into two shell command strings executed via child_process.execSync without sanitization or escaping. If filePath is attacker-controlled or derived from external input, this allows arbitrary command execution through shell metacharacters (e.g., '; rm -rf /', '$(...)', '&& ...').

util/get-git-hash-sync.js:13
high

Unescaped shell command construction

NPS-9718DF7A6B91

Second execSync call similarly concatenates filePath into the git log command string, providing another command injection vector with the same untrusted-input risk.

util/get-git-hash-sync.js:17
medium

Dynamic module loading

NPS-54C2F6008D8B

The code uses require(libName + '/package.json') where libName is a user-supplied parameter. If libName is not strictly validated before being passed to this function, an attacker could potentially load arbitrary package.json files from other installed packages or manipulate the module path resolution. This could lead to information disclosure of package metadata or unexpected code paths, though the impact is limited to reading package.json files.

util/get-lib-info.js:13
low

Swallowed exception masks state

NPS-1C2C07540C9B

The try/catch around the diff-index check silently ignores errors (the intended throw is commented out), meaning callers relying on the documented 'throws on uncommitted changes' contract may receive a hash for a dirty working tree. This is a correctness/robustness issue that can hide failures.

util/get-git-hash-sync.js:12
low

Potential path traversal in module resolution

NPS-7A2BAF39CB27

The dynamic require with computed input could allow path traversal if libName contains sequences like '../' to escape the intended package scope and load package.json from arbitrary locations accessible via Node's module resolution. This may expose internal package structure or configuration details but does not directly execute arbitrary code from the target file.

util/get-lib-info.js:13

Files reviewed

FileVerdictWhat the reviewer saw
util/get-git-hash-sync.js medium The utility executes git commands via execSync with unsanitized filePath interpolation, creating a command-injection risk if the argument is not fully trusted, though no data exfiltration, backdoor, or install-time execution was observed.
util/get-lib-info.js medium The code uses dynamic module loading with user-influenced input, creating a potential risk of unintended package.json disclosure, but no direct malicious patterns such as exfiltration, credential harvesting, or code execution were found.
cli/files-to-comparison-results.js safe Cleared by Jev triage; no further analysis needed
cli/format-table.js safe Cleared by Jev triage; no further analysis needed
cli/index.js safe This CLI utility uses standard Node.js modules for argument parsing, file globbing, and table formatting without any malicious patterns such as credential harvesting, obfuscation, network exfiltration, or process execution.
fixtures/index.js safe No malicious patterns detected; the file only exports a static require of a local module.
fixtures/input-data-types.js safe Cleared by Jev triage; no further analysis needed
index.js safe Cleared by Jev triage; no further analysis needed
karma.conf.js safe No malicious patterns detected in the Karma configuration file; it is a standard test runner setup with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
karma.conf.travis.js safe No malicious patterns detected
util/eachRecursive.js safe No malicious patterns detected
util/object-path.js safe Cleared by Jev triage; no further analysis needed
v8-profile/bench.js safe No malicious patterns detected; the file is a straightforward benchmark that imports local modules and runs stringification in a loop.

Scanned versions of fast-stable-stringify

VersionVerdictFilesScanned
1.0.0 Needs review 13 Oct 4, 2026

Frequently asked questions

Is fast-stable-stringify safe to use?

No confirmed malware was found in fast-stable-stringify@1.0.0, but the review flagged 2 high, 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does fast-stable-stringify contain malware?

No malware was identified in fast-stable-stringify@1.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was fast-stable-stringify checked?

Togoder Security downloaded the published npm package and had an AI model read its 13 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan fast-stable-stringify together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in fast-stable-stringify@1.0.0, cost nothing.

Related security reports