# function.prototype.name@1.1.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:40.000Z
- Files reviewed: 6
- Findings: 3 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/function.prototype.name
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package function.prototype.name@1.1.8 on Oct 6, 2026. An AI review of 6 source files produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Indirect code execution via module import

Finding ID: `NPS-9CF7B4A34E4F`

File: `auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-7E0C6CC45EFF`

File: `auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-FC4236118E85`

File: `auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [low] Benign re-export

Finding ID: `NPS-6CE13BF2A26A`

File: `helpers/functionsHaveNames.js:3`

This module simply re-exports the result of calling the 'functions-have-names' package. It is a thin compatibility shim with no data exfiltration, credential access, obfuscation, network activity, process spawning, or install-time side effects.

## Files reviewed

- `auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `helpers/functionsHaveNames.js` (safe): No malicious patterns detected; the file is a benign compatibility re-export of the functions-have-names module.
- `implementation.js` (safe): No malicious patterns detected; the code is a benign implementation of a Function.prototype.name sham/polyfill.
- `index.js` (safe): No malicious patterns detected
- `polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `shim.js` (safe): This is a legitimate ES5 polyfill for Function.prototype.name with no malicious patterns detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
