Summary
Togoder Security scanned the npm package fs-extra@11.3.3 on Oct 6, 2026. An AI review of 29 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Dynamic method wrapping of filesystem APIs
NPS-DF843B6EC818
The module builds a list of filesystem methods from the runtime fs object and wraps each with universalify.fromCallback, then exports them. It also does Object.assign(exports, fs) to clone all fs properties. This dynamic propagation means any unexpected or attacker-controlled additions to the fs object present at load time would be re-exported and promise-wrapped. This is a broad, dynamic surface that could mask or propagate tampered implementations, though no specific malicious payload is present in this file.
Import-time monkey-patching detection
NPS-BABF4AE94C70
The file contains logic that inspects fs.realpath.native and emits a warning if it is not a function, explicitly mentioning 'fs being monkey-patched'. While this is defensive, it indicates the library is aware of and operates in contexts where other code may have replaced (monkey-patched) Node.js fs methods. Because this module copies methods from graceful-fs and wraps them, if an attacker has already monkey-patched fs at import time, this library will faithfully wrap the malicious versions, potentially propagating compromised filesystem behavior to consumers.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/fs/index.js | medium | The code is a legitimate fs-extra-style promise wrapper over graceful-fs, but it dynamically inherits and wraps filesystem methods and explicitly guards against monkey-patched fs, which warrants a low-severity warning about propagation of tampered fs implementations. |
| lib/copy/copy-sync.js | safe | No malicious patterns detected; the code implements standard synchronous file/directory copy operations using the graceful-fs library. |
| lib/copy/copy.js | safe | No malicious patterns detected; the code is a legitimate file/directory copy utility from fs-extra with no network, credential, obfuscation, or process-spawning activity. |
| lib/copy/index.js | safe | No malicious patterns detected |
| lib/empty/index.js | safe | No malicious patterns detected |
| lib/ensure/file.js | safe | No malicious patterns detected |
| lib/ensure/index.js | safe | No malicious patterns detected; the module only re-exports file, link, and symlink creation helpers without any suspicious behavior. |
| lib/ensure/link.js | safe | No malicious patterns detected; the code only creates hard links with standard error handling and directory creation. |
| lib/ensure/symlink-paths.js | safe | No malicious patterns detected; the code only implements symlink path resolution logic using lstat, path operations, and file existence checks. |
| lib/ensure/symlink-type.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/ensure/symlink.js | safe | No malicious patterns detected |
| lib/esm.mjs | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/json/index.js | safe | No malicious patterns detected |
| lib/json/jsonfile.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/json/output-json-sync.js | safe | No malicious patterns detected |
| lib/json/output-json.js | safe | The code is a straightforward utility for writing JSON data to a file, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| lib/mkdirs/index.js | safe | No malicious patterns detected |
| lib/mkdirs/make-dir.js | safe | No malicious patterns detected; the code is a straightforward directory-creation utility with standard filesystem operations. |
| lib/mkdirs/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/move/index.js | safe | No malicious patterns detected; the file is a simple module wrapper for move and moveSync functions using universalify. |
| lib/move/move-sync.js | safe | No malicious patterns detected |
| lib/move/move.js | safe | No malicious patterns detected |
| lib/output-file/index.js | safe | No malicious patterns detected; the module only creates parent directories and writes files using standard filesystem operations. |
| lib/path-exists/index.js | safe | Cleared by Jev triage; no further analysis needed |
Show 4 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/remove/index.js | safe | No malicious patterns detected |
| lib/util/async.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/util/stat.js | safe | No malicious patterns detected; the code performs filesystem stat operations and path validation consistent with legitimate file utility logic. |
| lib/util/utimes.js | safe | No malicious patterns detected; the file provides standard file timestamp update utilities using fs.open/futimes/close with no network, credential, execution, or obfuscation concerns. |
Affected version ranges
None of the 2 scanned versions of fs-extra are flagged high or critical. The latest scanned version, 11.4.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 11.4.0 – 11.4.1 | Not scanned | 2 | >=11.4.0 <=11.4.1 | |
| 11.3.3 | Needs review | 1 | 11.3.3 | |
| 11.3.2 | No issues | 1 | 11.3.2 | |
| 8.1.0 – 10.1.0 | Not scanned | 3 | >=8.1.0 <=10.1.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of fs-extra
Frequently asked questions
Is fs-extra safe to use?
No confirmed malware was found in fs-extra@11.3.3, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does fs-extra contain malware?
No malware was identified in fs-extra@11.3.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was fs-extra checked?
Togoder Security downloaded the published npm package and had an AI model read its 29 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan fs-extra together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in fs-extra@11.3.3, cost nothing.