# globalthis@1.0.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:44.000Z
- Files reviewed: 6
- Findings: 3 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/globalthis
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package globalthis@1.0.4 on Oct 6, 2026. An AI review of 6 source files produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Indirect code execution via module import

Finding ID: `NPS-3CC67D5EB62C`

File: `auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-5FEC5EAAD146`

File: `auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-91175C3301E5`

File: `auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

### [low] Top-level code execution on import

Finding ID: `NPS-3AF4FF2A402E`

File: `implementation.browser.js:5`

The module immediately executes logic at import time (checking self/window and falling back to Function). This is standard module initialization behavior, not inherently malicious, but it does run top-level code as soon as the module is loaded.

### [low] Dynamic code execution

Finding ID: `NPS-175C6C859137`

File: `implementation.browser.js:8`

The code uses Function('return this')() as a fallback to obtain the global object. While this is a common polyfill pattern for universal/globalThis detection, use of the Function constructor to evaluate a string is a dynamic code execution vector. If the environment is manipulated (e.g., via prototype pollution or a compromised global context), this could theoretically execute unintended code. In most legitimate libraries this pattern is benign, but it warrants review.

## Files reviewed

- `auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `implementation.browser.js` (medium): The file is a common global-object polyfill with a minor dynamic code execution concern from Function('return this')(); no exfiltration, credential harvesting, or backdoor patterns were detected.
- `implementation.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): No malicious patterns detected; the code is a standard polyfill loader using define-properties.
- `polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `shim.js` (safe): This is a standard globalThis polyfill shim with no malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
