Summary
Togoder Security scanned the npm package get-intrinsic@1.3.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic code execution
NPS-C204B37A32B4
The getEvalledConstructor function uses the Function constructor to dynamically evaluate strings like 'async function () {}' to obtain constructors for intrinsics that are not directly accessible. While the inputs are static, hardcoded strings, this pattern is a form of eval and can be risky if input ever becomes tainted.
Access to Function constructor
NPS-6679AC387A3C
var $Function = Function; stores a reference to the global Function constructor, which can be used to create functions from strings. Again, only used with static strings in this file.
Use of eval
NPS-F236948C1DB2
The INTRINSICS object includes '%eval%': eval, exposing the global eval function. This is part of the intrinsic collection and not directly invoked here, but its inclusion could be abused by consumers of this module.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | This appears to be a legitimate polyfill/library for accessing JavaScript intrinsics (likely es-abstract's GetIntrinsic), using dynamic Function construction with hardcoded strings; no malicious data exfiltration, credential harvesting, network activity, or backdoor patterns were detected, but the dynamic code execution patterns warrant caution. |
Scanned versions of get-intrinsic
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.3.0 | Needs review | 1 | Oct 4, 2026 |
Frequently asked questions
Is get-intrinsic safe to use?
No confirmed malware was found in get-intrinsic@1.3.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does get-intrinsic contain malware?
No malware was identified in get-intrinsic@1.3.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was get-intrinsic checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan get-intrinsic together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in get-intrinsic@1.3.0, cost nothing.