Summary
Togoder Security scanned the npm package form-data@4.0.6 on Oct 4, 2026. An AI review of 3 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
Dynamic Header Injection Protected
NPS-913EAB86A820
The code includes escapeHeaderParam() to sanitize CR/LF/quote characters in field names and filenames, mitigating header injection / multipart part smuggling. Custom options.header values are used as-is, which is expected library behavior and caller-controlled.
HTTP Request Capability
NPS-8EA44EF661AA
The module includes a submit() method that can send the form data to an HTTP/HTTPS endpoint via http.request/https.request. However, this is a documented, intentional feature for submitting forms and not hidden exfiltration; it is invoked only by the caller.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/browser.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/form_data.js | safe | This is the legitimate form-data library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, child_process execution, or install-time hooks were detected. |
| lib/populate.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 3 scanned versions of form-data are flagged high or critical. The latest scanned version, 4.0.6, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of form-data
Frequently asked questions
Is form-data safe to use?
Our AI source review of form-data@4.0.6 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does form-data contain malware?
No malware was identified in form-data@4.0.6 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was form-data checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan form-data together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in form-data@4.0.6, cost nothing.