Togoder security

npm package security report

fs-extra@11.3.3 security report

Risky patterns found that deserve a look.

Needs review Version 11.3.3 Files reviewed 29 Size 42.4 KB Scanned

Summary

Togoder Security scanned the npm package fs-extra@11.3.3 on Oct 6, 2026. An AI review of 29 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

Dynamic method wrapping of filesystem APIs

NPS-DF843B6EC818

The module builds a list of filesystem methods from the runtime fs object and wraps each with universalify.fromCallback, then exports them. It also does Object.assign(exports, fs) to clone all fs properties. This dynamic propagation means any unexpected or attacker-controlled additions to the fs object present at load time would be re-exported and promise-wrapped. This is a broad, dynamic surface that could mask or propagate tampered implementations, though no specific malicious payload is present in this file.

lib/fs/index.js:66
low

Import-time monkey-patching detection

NPS-BABF4AE94C70

The file contains logic that inspects fs.realpath.native and emits a warning if it is not a function, explicitly mentioning 'fs being monkey-patched'. While this is defensive, it indicates the library is aware of and operates in contexts where other code may have replaced (monkey-patched) Node.js fs methods. Because this module copies methods from graceful-fs and wraps them, if an attacker has already monkey-patched fs at import time, this library will faithfully wrap the malicious versions, potentially propagating compromised filesystem behavior to consumers.

lib/fs/index.js:131

Files reviewed

FileVerdictWhat the reviewer saw
lib/fs/index.js medium The code is a legitimate fs-extra-style promise wrapper over graceful-fs, but it dynamically inherits and wraps filesystem methods and explicitly guards against monkey-patched fs, which warrants a low-severity warning about propagation of tampered fs implementations.
lib/copy/copy-sync.js safe No malicious patterns detected; the code implements standard synchronous file/directory copy operations using the graceful-fs library.
lib/copy/copy.js safe No malicious patterns detected; the code is a legitimate file/directory copy utility from fs-extra with no network, credential, obfuscation, or process-spawning activity.
lib/copy/index.js safe No malicious patterns detected
lib/empty/index.js safe No malicious patterns detected
lib/ensure/file.js safe No malicious patterns detected
lib/ensure/index.js safe No malicious patterns detected; the module only re-exports file, link, and symlink creation helpers without any suspicious behavior.
lib/ensure/link.js safe No malicious patterns detected; the code only creates hard links with standard error handling and directory creation.
lib/ensure/symlink-paths.js safe No malicious patterns detected; the code only implements symlink path resolution logic using lstat, path operations, and file existence checks.
lib/ensure/symlink-type.js safe Cleared by Jev triage; no further analysis needed
lib/ensure/symlink.js safe No malicious patterns detected
lib/esm.mjs safe Cleared by Jev triage; no further analysis needed
lib/index.js safe Cleared by Jev triage; no further analysis needed
lib/json/index.js safe No malicious patterns detected
lib/json/jsonfile.js safe Cleared by Jev triage; no further analysis needed
lib/json/output-json-sync.js safe No malicious patterns detected
lib/json/output-json.js safe The code is a straightforward utility for writing JSON data to a file, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
lib/mkdirs/index.js safe No malicious patterns detected
lib/mkdirs/make-dir.js safe No malicious patterns detected; the code is a straightforward directory-creation utility with standard filesystem operations.
lib/mkdirs/utils.js safe Cleared by Jev triage; no further analysis needed
lib/move/index.js safe No malicious patterns detected; the file is a simple module wrapper for move and moveSync functions using universalify.
lib/move/move-sync.js safe No malicious patterns detected
lib/move/move.js safe No malicious patterns detected
lib/output-file/index.js safe No malicious patterns detected; the module only creates parent directories and writes files using standard filesystem operations.
lib/path-exists/index.js safe Cleared by Jev triage; no further analysis needed
Show 4 more files
FileVerdictWhat the reviewer saw
lib/remove/index.js safe No malicious patterns detected
lib/util/async.js safe Cleared by Jev triage; no further analysis needed
lib/util/stat.js safe No malicious patterns detected; the code performs filesystem stat operations and path validation consistent with legitimate file utility logic.
lib/util/utimes.js safe No malicious patterns detected; the file provides standard file timestamp update utilities using fs.open/futimes/close with no network, credential, execution, or obfuscation concerns.

Affected version ranges

None of the 2 scanned versions of fs-extra are flagged high or critical. The latest scanned version, 11.4.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

8.1.011.4.1
VersionsVerdictCountRangeTop findings
11.4.0 – 11.4.1 Not scanned 2 >=11.4.0 <=11.4.1
11.3.3 Needs review 1 11.3.3
11.3.2 No issues 1 11.3.2
8.1.0 – 10.1.0 Not scanned 3 >=8.1.0 <=10.1.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of fs-extra

VersionVerdictFilesScanned
11.3.3 Needs review 29 Oct 6, 2026
11.3.2 No issues 29 May 15, 2026

Frequently asked questions

Is fs-extra safe to use?

No confirmed malware was found in fs-extra@11.3.3, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does fs-extra contain malware?

No malware was identified in fs-extra@11.3.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was fs-extra checked?

Togoder Security downloaded the published npm package and had an AI model read its 29 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan fs-extra together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in fs-extra@11.3.3, cost nothing.

Related security reports