Togoder security

npm package security report

graceful-fs@4.2.10 security report

Risky patterns found that deserve a look.

Needs review Version 4.2.10 Files reviewed 4 Size 25.3 KB Scanned

Summary

Togoder Security scanned the npm package graceful-fs@4.2.10 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
2
low

Findings 4

medium

Global process object modification

NPS-803C7A3ECB87

The code permanently overrides process.cwd and process.chdir at module load time, affecting all code in the process. While this is the intended behavior of graceful-fs polyfills, monkey-patching core Node.js globals is a broad side effect that can interfere with other modules and is a common technique used by malicious packages to hide their own file operations from security tooling.

polyfills.js:8
medium

Filesystem monkey-patching

NPS-4E7220028E98

The patch() function rewrites numerous fs methods (chown, chmod, stat, read, rename, lchmod, lchown, lutimes) and silently swallows certain errors (EINVAL, EPERM, ENOSYS) via chownErOk. This can mask real permission failures and is a known pattern that malware sometimes leverages to hide its own file operations.

polyfills.js:30
low

Environment-variable-controlled platform detection

NPS-D96049FEB3E4

The platform is derived from process.env.GRACEFUL_FS_PLATFORM, which an attacker (or a compromised build environment) could set to force the Windows-specific rename retry path on non-Windows systems, or vice versa. This is benign in context but represents an environment-dependent behavioral branch.

polyfills.js:5
low

Timing-based retry loop

NPS-6DE564AF656B

The Windows rename wrapper retries for up to 60 seconds using Date.now() and setTimeout with backoff. This is documented as an anti-virus workaround, but long-lived retry loops can also be abused to delay or mask file operations.

polyfills.js:100

Files reviewed

FileVerdictWhat the reviewer saw
polyfills.js medium This is the legitimate graceful-fs polyfill module; it monkey-patches core fs and process globals (cwd/chdir) and swallows certain permission errors, which are benign but broad global modifications worth flagging.
clone.js safe Cleared by Jev triage; no further analysis needed
graceful-fs.js safe No malicious patterns detected
legacy-streams.js safe No malicious patterns detected; this is a legacy fs stream shim with no exfiltration, credential harvesting, code execution, or other suspicious behavior.

Affected version ranges

None of the 2 scanned versions of graceful-fs are flagged high or critical. The latest scanned version, 4.2.11, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

4.2.104.2.11
VersionsVerdictCountRangeTop findings
4.2.11 No issues 1 4.2.11
4.2.10 Needs review 1 4.2.10 Global process object modification; Filesystem monkey-patching

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of graceful-fs

VersionVerdictFilesScanned
4.2.11 No issues 4 Oct 6, 2026
4.2.10 Needs review 4 Oct 6, 2026

Frequently asked questions

Is graceful-fs safe to use?

No confirmed malware was found in graceful-fs@4.2.10, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does graceful-fs contain malware?

No malware was identified in graceful-fs@4.2.10 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was graceful-fs checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan graceful-fs together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in graceful-fs@4.2.10, cost nothing.

Related security reports