# fs-extra@11.3.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:42.000Z
- Files reviewed: 29
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/fs-extra@11.3.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package fs-extra@11.3.3 on Oct 6, 2026. An AI review of 29 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Dynamic method wrapping of filesystem APIs

Finding ID: `NPS-DF843B6EC818`

File: `lib/fs/index.js:66`

The module builds a list of filesystem methods from the runtime fs object and wraps each with universalify.fromCallback, then exports them. It also does Object.assign(exports, fs) to clone all fs properties. This dynamic propagation means any unexpected or attacker-controlled additions to the fs object present at load time would be re-exported and promise-wrapped. This is a broad, dynamic surface that could mask or propagate tampered implementations, though no specific malicious payload is present in this file.

### [low] Import-time monkey-patching detection

Finding ID: `NPS-BABF4AE94C70`

File: `lib/fs/index.js:131`

The file contains logic that inspects fs.realpath.native and emits a warning if it is not a function, explicitly mentioning 'fs being monkey-patched'. While this is defensive, it indicates the library is aware of and operates in contexts where other code may have replaced (monkey-patched) Node.js fs methods. Because this module copies methods from graceful-fs and wraps them, if an attacker has already monkey-patched fs at import time, this library will faithfully wrap the malicious versions, potentially propagating compromised filesystem behavior to consumers.

## Files reviewed

- `lib/fs/index.js` (medium): The code is a legitimate fs-extra-style promise wrapper over graceful-fs, but it dynamically inherits and wraps filesystem methods and explicitly guards against monkey-patched fs, which warrants a low-severity warning about propagation of tampered fs implementations.
- `lib/copy/copy-sync.js` (safe): No malicious patterns detected; the code implements standard synchronous file/directory copy operations using the graceful-fs library.
- `lib/copy/copy.js` (safe): No malicious patterns detected; the code is a legitimate file/directory copy utility from fs-extra with no network, credential, obfuscation, or process-spawning activity.
- `lib/copy/index.js` (safe): No malicious patterns detected
- `lib/empty/index.js` (safe): No malicious patterns detected
- `lib/ensure/file.js` (safe): No malicious patterns detected
- `lib/ensure/index.js` (safe): No malicious patterns detected; the module only re-exports file, link, and symlink creation helpers without any suspicious behavior.
- `lib/ensure/link.js` (safe): No malicious patterns detected; the code only creates hard links with standard error handling and directory creation.
- `lib/ensure/symlink-paths.js` (safe): No malicious patterns detected; the code only implements symlink path resolution logic using lstat, path operations, and file existence checks.
- `lib/ensure/symlink-type.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/ensure/symlink.js` (safe): No malicious patterns detected
- `lib/esm.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/json/index.js` (safe): No malicious patterns detected
- `lib/json/jsonfile.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/json/output-json-sync.js` (safe): No malicious patterns detected
- `lib/json/output-json.js` (safe): The code is a straightforward utility for writing JSON data to a file, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/mkdirs/index.js` (safe): No malicious patterns detected
- `lib/mkdirs/make-dir.js` (safe): No malicious patterns detected; the code is a straightforward directory-creation utility with standard filesystem operations.
- `lib/mkdirs/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/move/index.js` (safe): No malicious patterns detected; the file is a simple module wrapper for move and moveSync functions using universalify.
- `lib/move/move-sync.js` (safe): No malicious patterns detected
- `lib/move/move.js` (safe): No malicious patterns detected
- `lib/output-file/index.js` (safe): No malicious patterns detected; the module only creates parent directories and writes files using standard filesystem operations.
- `lib/path-exists/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/remove/index.js` (safe): No malicious patterns detected
- `lib/util/async.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/stat.js` (safe): No malicious patterns detected; the code performs filesystem stat operations and path validation consistent with legitimate file utility logic.
- `lib/util/utimes.js` (safe): No malicious patterns detected; the file provides standard file timestamp update utilities using fs.open/futimes/close with no network, credential, execution, or obfuscation concerns.

## Version ranges

None of the 2 scanned versions of fs-extra are flagged high or critical. The latest scanned version, 11.4.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 11.4.0 – 11.4.1 (`>=11.4.0 <=11.4.1`): not scanned
- 11.3.3 (`11.3.3`): medium
- 11.3.2 (`11.3.2`): clean
- 8.1.0 – 10.1.0 (`>=8.1.0 <=10.1.0`): not scanned

## Scanned versions

- [11.3.3](https://security.togoder.click/npm/fs-extra@11.3.3): medium, 2026-10-06T14:16:42.000Z
- [11.3.2](https://security.togoder.click/npm/fs-extra@11.3.2): safe, 2026-05-15T12:30:45.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
