# graceful-fs@4.2.10 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:39.000Z
- Files reviewed: 4
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/graceful-fs@4.2.10
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package graceful-fs@4.2.10 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Global process object modification

Finding ID: `NPS-803C7A3ECB87`

File: `polyfills.js:8`

The code permanently overrides process.cwd and process.chdir at module load time, affecting all code in the process. While this is the intended behavior of graceful-fs polyfills, monkey-patching core Node.js globals is a broad side effect that can interfere with other modules and is a common technique used by malicious packages to hide their own file operations from security tooling.

### [medium] Filesystem monkey-patching

Finding ID: `NPS-4E7220028E98`

File: `polyfills.js:30`

The patch() function rewrites numerous fs methods (chown, chmod, stat, read, rename, lchmod, lchown, lutimes) and silently swallows certain errors (EINVAL, EPERM, ENOSYS) via chownErOk. This can mask real permission failures and is a known pattern that malware sometimes leverages to hide its own file operations.

### [low] Environment-variable-controlled platform detection

Finding ID: `NPS-D96049FEB3E4`

File: `polyfills.js:5`

The platform is derived from process.env.GRACEFUL_FS_PLATFORM, which an attacker (or a compromised build environment) could set to force the Windows-specific rename retry path on non-Windows systems, or vice versa. This is benign in context but represents an environment-dependent behavioral branch.

### [low] Timing-based retry loop

Finding ID: `NPS-6DE564AF656B`

File: `polyfills.js:100`

The Windows rename wrapper retries for up to 60 seconds using Date.now() and setTimeout with backoff. This is documented as an anti-virus workaround, but long-lived retry loops can also be abused to delay or mask file operations.

## Files reviewed

- `polyfills.js` (medium): This is the legitimate graceful-fs polyfill module; it monkey-patches core fs and process globals (cwd/chdir) and swallows certain permission errors, which are benign but broad global modifications worth flagging.
- `clone.js` (safe): Cleared by Jev triage; no further analysis needed
- `graceful-fs.js` (safe): No malicious patterns detected
- `legacy-streams.js` (safe): No malicious patterns detected; this is a legacy fs stream shim with no exfiltration, credential harvesting, code execution, or other suspicious behavior.

## Version ranges

None of the 2 scanned versions of graceful-fs are flagged high or critical. The latest scanned version, 4.2.11, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.2.11 (`4.2.11`): clean
- 4.2.10 (`4.2.10`): medium (Global process object modification +1 more)

## Scanned versions

- [4.2.11](https://security.togoder.click/npm/graceful-fs@4.2.11): safe, 2026-10-06T14:16:46.000Z
- [4.2.10](https://security.togoder.click/npm/graceful-fs@4.2.10): medium, 2026-10-06T14:11:39.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
