Summary
Togoder Security scanned the npm package fast-stable-stringify@1.0.0 on Oct 4, 2026. An AI review of 13 source files produced 2 high, 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Command injection via shell execSync
NPS-D226154C91AB
The function passes its filePath parameter directly into two shell command strings executed via child_process.execSync without sanitization or escaping. If filePath is attacker-controlled or derived from external input, this allows arbitrary command execution through shell metacharacters (e.g., '; rm -rf /', '$(...)', '&& ...').
Unescaped shell command construction
NPS-9718DF7A6B91
Second execSync call similarly concatenates filePath into the git log command string, providing another command injection vector with the same untrusted-input risk.
Dynamic module loading
NPS-54C2F6008D8B
The code uses require(libName + '/package.json') where libName is a user-supplied parameter. If libName is not strictly validated before being passed to this function, an attacker could potentially load arbitrary package.json files from other installed packages or manipulate the module path resolution. This could lead to information disclosure of package metadata or unexpected code paths, though the impact is limited to reading package.json files.
Swallowed exception masks state
NPS-1C2C07540C9B
The try/catch around the diff-index check silently ignores errors (the intended throw is commented out), meaning callers relying on the documented 'throws on uncommitted changes' contract may receive a hash for a dirty working tree. This is a correctness/robustness issue that can hide failures.
Potential path traversal in module resolution
NPS-7A2BAF39CB27
The dynamic require with computed input could allow path traversal if libName contains sequences like '../' to escape the intended package scope and load package.json from arbitrary locations accessible via Node's module resolution. This may expose internal package structure or configuration details but does not directly execute arbitrary code from the target file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| util/get-git-hash-sync.js | medium | The utility executes git commands via execSync with unsanitized filePath interpolation, creating a command-injection risk if the argument is not fully trusted, though no data exfiltration, backdoor, or install-time execution was observed. |
| util/get-lib-info.js | medium | The code uses dynamic module loading with user-influenced input, creating a potential risk of unintended package.json disclosure, but no direct malicious patterns such as exfiltration, credential harvesting, or code execution were found. |
| cli/files-to-comparison-results.js | safe | Cleared by Jev triage; no further analysis needed |
| cli/format-table.js | safe | Cleared by Jev triage; no further analysis needed |
| cli/index.js | safe | This CLI utility uses standard Node.js modules for argument parsing, file globbing, and table formatting without any malicious patterns such as credential harvesting, obfuscation, network exfiltration, or process execution. |
| fixtures/index.js | safe | No malicious patterns detected; the file only exports a static require of a local module. |
| fixtures/input-data-types.js | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| karma.conf.js | safe | No malicious patterns detected in the Karma configuration file; it is a standard test runner setup with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| karma.conf.travis.js | safe | No malicious patterns detected |
| util/eachRecursive.js | safe | No malicious patterns detected |
| util/object-path.js | safe | Cleared by Jev triage; no further analysis needed |
| v8-profile/bench.js | safe | No malicious patterns detected; the file is a straightforward benchmark that imports local modules and runs stringification in a loop. |
Frequently asked questions
Is fast-stable-stringify safe to use?
No confirmed malware was found in fast-stable-stringify@1.0.0, but the review flagged 2 high, 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does fast-stable-stringify contain malware?
No malware was identified in fast-stable-stringify@1.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was fast-stable-stringify checked?
Togoder Security downloaded the published npm package and had an AI model read its 13 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan fast-stable-stringify together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in fast-stable-stringify@1.0.0, cost nothing.