Togoder security

npm package security report

generator-function npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.0.1 Files reviewed 4 Size 879 B Scanned

Summary

Togoder Security scanned the npm package generator-function@2.0.1 on Oct 4, 2026. An AI review of 4 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
1
low

Findings 2

medium

Dynamic code execution via Function constructor

NPS-5A747D325370

The code accesses the Function constructor through a generator function instance (function* () {}.constructor) and exports it. This is a common technique to obtain the Function constructor without triggering lint rules or static analysis checks, and can be used to dynamically execute arbitrary code (equivalent to new Function). While the code itself only caches and returns the constructor, exposing this pattern in a public package could be leveraged by downstream consumers or indicate an attempt to evade code review tooling.

index.js:4
low

Dynamic code execution

NPS-2372E3BA2DD2

Uses the Function constructor with a fixed string to detect the GeneratorFunction constructor. This is a dynamic code execution pattern and may be flagged by security tooling or blocked by strict CSP, though no external or user-controlled input is evaluated.

legacy.js:11

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The file exports a cached reference to the Function constructor via an unusual generator-based access pattern, which is a code-execution primitive often used for obfuscation or lint evasion, though no active malicious behavior is present in this snippet.
legacy.js medium The file uses Function constructor for a benign feature detection, presenting a low-risk dynamic code execution pattern without exfiltration, environment access, or other malicious behavior.
index.mjs safe Cleared by Jev triage; no further analysis needed
require.mjs safe Cleared by Jev triage; no further analysis needed

Scanned versions of generator-function

VersionVerdictFilesScanned
2.0.1 Needs review 4 Oct 4, 2026

Frequently asked questions

Is generator-function safe to use?

No confirmed malware was found in generator-function@2.0.1, but the review flagged 1 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does generator-function contain malware?

No malware was identified in generator-function@2.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was generator-function checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan generator-function together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in generator-function@2.0.1, cost nothing.

Related security reports