Togoder security

npm package security report

get-intrinsic@1.3.0 security report

Risky patterns found that deserve a look.

Needs review Version 1.3.0 Files reviewed 1 Size 14.1 KB Scanned

Summary

Togoder Security scanned the npm package get-intrinsic@1.3.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

Dynamic code execution

NPS-C204B37A32B4

The getEvalledConstructor function uses the Function constructor to dynamically evaluate strings like 'async function () {}' to obtain constructors for intrinsics that are not directly accessible. While the inputs are static, hardcoded strings, this pattern is a form of eval and can be risky if input ever becomes tainted.

index.js:28
low

Access to Function constructor

NPS-6679AC387A3C

var $Function = Function; stores a reference to the global Function constructor, which can be used to create functions from strings. Again, only used with static strings in this file.

index.js:22
low

Use of eval

NPS-F236948C1DB2

The INTRINSICS object includes '%eval%': eval, exposing the global eval function. This is part of the intrinsic collection and not directly invoked here, but its inclusion could be abused by consumers of this module.

index.js:96

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium This appears to be a legitimate polyfill/library for accessing JavaScript intrinsics (likely es-abstract's GetIntrinsic), using dynamic Function construction with hardcoded strings; no malicious data exfiltration, credential harvesting, network activity, or backdoor patterns were detected, but the dynamic code execution patterns warrant caution.

Frequently asked questions

Is get-intrinsic safe to use?

No confirmed malware was found in get-intrinsic@1.3.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does get-intrinsic contain malware?

No malware was identified in get-intrinsic@1.3.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was get-intrinsic checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan get-intrinsic together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in get-intrinsic@1.3.0, cost nothing.

Related security reports