Summary
Togoder Security scanned the npm package graceful-fs@4.2.11 on Oct 6, 2026. An AI review of 4 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
Environment variable access
NPS-765D1B694444
Reads process.env.GRACEFUL_FS_PLATFORM to allow overriding the platform detection, which is a benign configuration option, not credential harvesting.
Monkey-patching global process object
NPS-B5F4DFBD0E18
Overrides process.cwd and process.chdir to cache/clear the current working directory. This is a known behavior of the graceful-fs package to work around Node.js issues, not malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| clone.js | safe | Cleared by Jev triage; no further analysis needed |
| graceful-fs.js | safe | No malicious patterns detected |
| legacy-streams.js | safe | No malicious patterns detected; this is a legacy fs stream shim with no exfiltration, credential harvesting, code execution, or other suspicious behavior. |
| polyfills.js | safe | The code is the legitimate graceful-fs polyfills module that patches Node.js fs methods for compatibility; no malicious patterns such as exfiltration, credential harvesting, or code execution were found. |
Affected version ranges
None of the 2 scanned versions of graceful-fs are flagged high or critical. The latest scanned version, 4.2.11, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.2.11 | No issues | 1 | 4.2.11 | |
| 4.2.10 | Needs review | 1 | 4.2.10 | Global process object modification; Filesystem monkey-patching |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of graceful-fs
Frequently asked questions
Is graceful-fs safe to use?
Our AI source review of graceful-fs@4.2.11 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does graceful-fs contain malware?
No malware was identified in graceful-fs@4.2.11 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was graceful-fs checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan graceful-fs together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in graceful-fs@4.2.11, cost nothing.