# graceful-fs@4.2.11 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:16:46.000Z
- Files reviewed: 4
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/graceful-fs@4.2.11
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package graceful-fs@4.2.11 on Oct 6, 2026. An AI review of 4 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Environment variable access

Finding ID: `NPS-765D1B694444`

File: `polyfills.js:6`

Reads process.env.GRACEFUL_FS_PLATFORM to allow overriding the platform detection, which is a benign configuration option, not credential harvesting.

### [low] Monkey-patching global process object

Finding ID: `NPS-B5F4DFBD0E18`

File: `polyfills.js:9`

Overrides process.cwd and process.chdir to cache/clear the current working directory. This is a known behavior of the graceful-fs package to work around Node.js issues, not malicious.

## Files reviewed

- `clone.js` (safe): Cleared by Jev triage; no further analysis needed
- `graceful-fs.js` (safe): No malicious patterns detected
- `legacy-streams.js` (safe): No malicious patterns detected; this is a legacy fs stream shim with no exfiltration, credential harvesting, code execution, or other suspicious behavior.
- `polyfills.js` (safe): The code is the legitimate graceful-fs polyfills module that patches Node.js fs methods for compatibility; no malicious patterns such as exfiltration, credential harvesting, or code execution were found.

## Version ranges

None of the 2 scanned versions of graceful-fs are flagged high or critical. The latest scanned version, 4.2.11, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.2.11 (`4.2.11`): clean
- 4.2.10 (`4.2.10`): medium (Global process object modification +1 more)

## Scanned versions

- [4.2.11](https://security.togoder.click/npm/graceful-fs@4.2.11): safe, 2026-10-06T14:16:46.000Z
- [4.2.10](https://security.togoder.click/npm/graceful-fs@4.2.10): medium, 2026-10-06T14:11:39.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
