Togoder security

npm package security report

flatted@3.4.4 security report

Risky patterns found that deserve a look.

Needs review Version 3.4.4 Files reviewed 6 Size 14.9 KB Scanned

Summary

Togoder Security scanned the npm package flatted@3.4.4 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Obfuscated code

NPS-40F846DC8655

The entire file is minified and heavily obfuscated with single-letter variable names, making it difficult to understand. This is a common technique used to hide malicious behavior. While it appears to implement a custom JSON stringify/parse (likely for circular references), the obfuscation obscures the actual functionality.

esm.js:1
medium

Lack of clarity

NPS-8C3C0AAD7E30

The code is a minified version of what appears to be the 'flatted' library, which serializes cyclic JSON. Without proper documentation or source maps, it is impossible to fully audit. This could be a supply chain risk if the package is not from a trusted source.

esm.js:1
low

Dynamic code execution

NPS-237B738EBC16

The code uses JSON.parse and JSON.stringify indirectly via destructuring, but there is no explicit eval or new Function. However, the custom parsing logic could be exploited if the input is untrusted, but it does not execute arbitrary code.

esm.js

Files reviewed

FileVerdictWhat the reviewer saw
esm.js medium The code is heavily obfuscated and likely implements a JSON cyclic reference serializer, but the obfuscation raises concerns about potential hidden behavior, though no explicit malicious patterns were detected.
cjs/index.js safe No malicious patterns detected; the code is a legitimate JSON recursion serialization utility with no network, filesystem, process, or dynamic execution behavior.
es.js safe No malicious patterns detected
esm/index.js safe No malicious patterns detected; the code is a legitimate JSON serialization library (flatted) that only parses/stringifies values in-memory without network, filesystem, or process access.
index.js safe No malicious patterns detected; the code is a legitimate JSON serialization library with no network, filesystem, or process access.
min.js safe No malicious patterns detected; this is a legitimate minified JSON.stringify wrapper (flatted) with no network, filesystem, process, or dynamic code execution behavior.

Frequently asked questions

Is flatted safe to use?

No confirmed malware was found in flatted@3.4.4, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does flatted contain malware?

No malware was identified in flatted@3.4.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was flatted checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan flatted together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in flatted@3.4.4, cost nothing.

Related security reports