Summary
Togoder Security scanned the npm package flatted@3.4.4 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Obfuscated code
NPS-40F846DC8655
The entire file is minified and heavily obfuscated with single-letter variable names, making it difficult to understand. This is a common technique used to hide malicious behavior. While it appears to implement a custom JSON stringify/parse (likely for circular references), the obfuscation obscures the actual functionality.
Lack of clarity
NPS-8C3C0AAD7E30
The code is a minified version of what appears to be the 'flatted' library, which serializes cyclic JSON. Without proper documentation or source maps, it is impossible to fully audit. This could be a supply chain risk if the package is not from a trusted source.
Dynamic code execution
NPS-237B738EBC16
The code uses JSON.parse and JSON.stringify indirectly via destructuring, but there is no explicit eval or new Function. However, the custom parsing logic could be exploited if the input is untrusted, but it does not execute arbitrary code.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm.js | medium | The code is heavily obfuscated and likely implements a JSON cyclic reference serializer, but the obfuscation raises concerns about potential hidden behavior, though no explicit malicious patterns were detected. |
| cjs/index.js | safe | No malicious patterns detected; the code is a legitimate JSON recursion serialization utility with no network, filesystem, process, or dynamic execution behavior. |
| es.js | safe | No malicious patterns detected |
| esm/index.js | safe | No malicious patterns detected; the code is a legitimate JSON serialization library (flatted) that only parses/stringifies values in-memory without network, filesystem, or process access. |
| index.js | safe | No malicious patterns detected; the code is a legitimate JSON serialization library with no network, filesystem, or process access. |
| min.js | safe | No malicious patterns detected; this is a legitimate minified JSON.stringify wrapper (flatted) with no network, filesystem, process, or dynamic code execution behavior. |
Scanned versions of flatted
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 3.4.4 | Needs review | 6 | Oct 6, 2026 |
Frequently asked questions
Is flatted safe to use?
No confirmed malware was found in flatted@3.4.4, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does flatted contain malware?
No malware was identified in flatted@3.4.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was flatted checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan flatted together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in flatted@3.4.4, cost nothing.