Summary
Togoder Security scanned the npm package graceful-fs@4.2.10 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Global process object modification
NPS-803C7A3ECB87
The code permanently overrides process.cwd and process.chdir at module load time, affecting all code in the process. While this is the intended behavior of graceful-fs polyfills, monkey-patching core Node.js globals is a broad side effect that can interfere with other modules and is a common technique used by malicious packages to hide their own file operations from security tooling.
Filesystem monkey-patching
NPS-4E7220028E98
The patch() function rewrites numerous fs methods (chown, chmod, stat, read, rename, lchmod, lchown, lutimes) and silently swallows certain errors (EINVAL, EPERM, ENOSYS) via chownErOk. This can mask real permission failures and is a known pattern that malware sometimes leverages to hide its own file operations.
Environment-variable-controlled platform detection
NPS-D96049FEB3E4
The platform is derived from process.env.GRACEFUL_FS_PLATFORM, which an attacker (or a compromised build environment) could set to force the Windows-specific rename retry path on non-Windows systems, or vice versa. This is benign in context but represents an environment-dependent behavioral branch.
Timing-based retry loop
NPS-6DE564AF656B
The Windows rename wrapper retries for up to 60 seconds using Date.now() and setTimeout with backoff. This is documented as an anti-virus workaround, but long-lived retry loops can also be abused to delay or mask file operations.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| polyfills.js | medium | This is the legitimate graceful-fs polyfill module; it monkey-patches core fs and process globals (cwd/chdir) and swallows certain permission errors, which are benign but broad global modifications worth flagging. |
| clone.js | safe | Cleared by Jev triage; no further analysis needed |
| graceful-fs.js | safe | No malicious patterns detected |
| legacy-streams.js | safe | No malicious patterns detected; this is a legacy fs stream shim with no exfiltration, credential harvesting, code execution, or other suspicious behavior. |
Affected version ranges
None of the 2 scanned versions of graceful-fs are flagged high or critical. The latest scanned version, 4.2.11, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.2.11 | No issues | 1 | 4.2.11 | |
| 4.2.10 | Needs review | 1 | 4.2.10 | Global process object modification; Filesystem monkey-patching |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of graceful-fs
Frequently asked questions
Is graceful-fs safe to use?
No confirmed malware was found in graceful-fs@4.2.10, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does graceful-fs contain malware?
No malware was identified in graceful-fs@4.2.10 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was graceful-fs checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan graceful-fs together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in graceful-fs@4.2.10, cost nothing.