Togoder security

npm package security report

handlebars@4.7.9 security report

Risky patterns found that deserve a look.

Needs review Version 4.7.9 Files reviewed 97 Size 2.4 MB Scanned

Summary

Togoder Security scanned the npm package handlebars@4.7.9 on Oct 6, 2026. An AI review of 97 source files produced 3 medium, 11 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
11
low

Findings 14

medium

Dynamic code execution

NPS-181CCF94254C

The compiler uses Function.apply(...) to construct compiled template functions dynamically. This is normal for a template compiler, but it is still runtime code generation from generated strings; if an attacker can influence the AST/opcodes or helper/decorator names, this could become a code-injection sink. No direct external attacker-controlled input path is visible in this file alone, but it is a high-risk primitive to audit.

lib/handlebars/compiler/javascript-compiler.js
medium

Potential template/helper resolution issue

NPS-3568A34700E8

Decorator, helper, and partial names are resolved and then inserted into generated function bodies via nameLookup/setupHelperArgs/registerDecorator. If the upstream parser allows unsanitized names, these could be emitted into generated JavaScript. The file relies on caller-side validation, so this is a risky boundary rather than a confirmed vulnerability.

lib/handlebars/compiler/javascript-compiler.js
medium

require.extensions hook installation

NPS-5969859F80EC

The code registers a global require() handler for .handlebars and .hbs files. This hook executes automatically whenever a .handlebars or .hbs file is imported, which could be leveraged to execute arbitrary code if an attacker controls the template files or the module resolution process. While this is a standard feature of Handlebars, it represents a potential attack surface for code execution at import time.

lib/index.js:22
low

conditional require of source-map library

NPS-F82DCEFCEBFD

The module conditionally requires the 'source-map' package when not running in an AMD environment. This is a legitimate optional dependency used for source map generation and is wrapped in a try/catch. No malicious behavior is present.

dist/amd/handlebars/compiler/code-gen.js:11
low

Object.prototype pollution (temporary)

NPS-31DD4D51CDC3

The polyfill temporarily defines a '__magic__' getter on Object.prototype to obtain a reference to the global object in environments without globalThis. It deletes the property immediately after use. This is a known, documented technique (Mathias Bynens' globalThis polyfill) used by the legitimate Handlebars library, not a malicious pattern.

dist/amd/handlebars/no-conflict.js:8
low

Global prototype modification

NPS-085541DFA963

The code temporarily defines a getter on Object.prototype (__magic__) to polyfill globalThis in legacy environments, then deletes it. This is a well-known, standard polyfill pattern from Mathias Bynens and is immediately cleaned up. It is not used maliciously.

dist/cjs/handlebars/no-conflict.js:11
low

Source map exposure

NPS-A97224F1114E

The file includes an inline base64-encoded source map (sourceMappingURL) which reveals the original source code. This is a common practice for debugging and is not malicious, but it could be considered information disclosure if not intended.

dist/cjs/handlebars/runtime.js
low

Dynamic code compilation

NPS-351F9264FEEF

The code calls env.compile(partial, ...) when a partial cannot be resolved at runtime. This is part of Handlebars' standard runtime-only mode behavior, allowing compilation of partials from strings. While this does execute a compile function from the environment, it is a documented feature and not obfuscated or externally controlled. It does not constitute a backdoor or arbitrary code execution vulnerability in itself.

dist/cjs/handlebars/runtime.js:77
low

Dynamic require

NPS-301922990730

The minify function uses require('uglify-js') for an optional dependency. This is a legitimate use case for an optional minification dependency, not a malicious backdoor. The require is guarded by require.resolve and only executed if uglify-js exists.

dist/cjs/precompiler.js
low

File system writes

NPS-B4C43DC8D80F

Uses fs.writeFileSync to write source map and output files. This is expected behavior for a precompiler CLI tool that generates files based on user-provided paths.

dist/cjs/precompiler.js
low

Stdin reading

NPS-516F46A10026

Reads from process.stdin when a template string is '-'. This is standard CLI behavior for accepting piped input, not malicious.

dist/cjs/precompiler.js
low

conditional dynamic import

NPS-C54EF9244DDC

The code attempts to require('source-map') at module load time when not in an AMD environment. This is a standard, expected dependency for the Handlebars compiler to generate source maps. The import is wrapped in try/catch and used only for source mapping, not for executing untrusted code or exfiltrating data.

lib/handlebars/compiler/code-gen.js:11
low

Error-handling/DoS behavior

NPS-C27ED6DF191E

registerDecorator explicitly throws when a decorator is missing to avoid a TypeError crash. This is a defensive change, but it also means templates can be crafted to trigger exceptions during compilation/execution if decorator resolution is attacker-influenced.

lib/handlebars/compiler/javascript-compiler.js
low

Top-level code execution on import

NPS-1306F2E41A94

The module registers require.extensions hooks at import time. This side effect modifies global state and could interfere with other modules or be exploited if the package is compromised. The code runs automatically when the package is required, without explicit user action.

lib/index.js:22

Files reviewed

FileVerdictWhat the reviewer saw
lib/handlebars/compiler/javascript-compiler.js medium This is a legitimate Handlebars compiler file with no obvious data exfiltration, credential harvesting, backdoors, or install-time payloads, but it contains expected high-risk dynamic code generation primitives that warrant focused audit.
lib/index.js medium The code appears to be the legitimate Handlebars library entry point, but it installs global require.extensions hooks that execute on import and could pose a code execution risk if template files are attacker-controlled.
bin/.eslintrc.js safe Cleared by Jev triage; no further analysis needed
dist/amd/handlebars.js safe This is a standard Handlebars.js AMD distribution file that imports and wires together the library's runtime and compiler modules with no malicious patterns detected.
dist/amd/handlebars.runtime.js safe No malicious patterns detected; this is a standard Handlebars runtime module loader with only a benign source map.
dist/amd/handlebars/base.js safe This is a legitimate Handlebars.js base module (v4.7.9) defining the core environment, helpers, and decorator registration APIs; no malicious patterns such as exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning were detected.
dist/amd/handlebars/compiler/ast.js safe No malicious patterns detected
dist/amd/handlebars/compiler/base.js safe The code is a legitimate Handlebars compiler base module that performs AST parsing and validation without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file operations.
dist/amd/handlebars/compiler/code-gen.js safe Code is a legitimate Handlebars compiler code generation module; no malicious patterns detected.
dist/amd/handlebars/compiler/compiler.js safe This is the legitimate Handlebars compiler module containing only AST-to-opcode compilation logic, with no malicious patterns, network activity, or dynamic code execution.
dist/amd/handlebars/compiler/helpers.js safe No malicious patterns detected; this is legitimate Handlebars compiler helper code with no network, filesystem, process, or dynamic execution activity.
dist/amd/handlebars/compiler/printer.js safe No malicious patterns detected
dist/amd/handlebars/compiler/visitor.js safe No malicious patterns detected
dist/amd/handlebars/compiler/whitespace-control.js safe No malicious patterns detected; this is legitimate Handlebars whitespace control compiler code.
dist/amd/handlebars/decorators.js safe This is a standard Handlebars decorator registration module with no suspicious patterns, network activity, or code execution risks.
dist/amd/handlebars/decorators/inline.js safe The file is a legitimate Handlebars inline decorator implementation with no malicious patterns detected.
dist/amd/handlebars/exception.js safe No malicious patterns detected; this is a standard Handlebars exception utility that extends Error with location metadata and contains no network, filesystem, process, or dynamic code execution behavior.
dist/amd/handlebars/helpers.js safe No malicious patterns detected; this is a standard Handlebars.js module that registers default helpers and manipulates helper hooks without any suspicious behavior.
dist/amd/handlebars/helpers/block-helper-missing.js safe No malicious patterns detected; this is a standard Handlebars helper implementation.
dist/amd/handlebars/helpers/each.js safe This is a legitimate Handlebars.js 'each' helper implementation with no malicious patterns, obfuscation, or suspicious behavior.
dist/amd/handlebars/helpers/helper-missing.js safe No malicious patterns detected in this Handlebars helper-missing module, which only registers a template helper that throws an exception for missing helpers.
dist/amd/handlebars/helpers/if.js safe No malicious patterns detected; this is the legitimate Handlebars built-in 'if' and 'unless' helper implementation.
dist/amd/handlebars/helpers/log.js safe No malicious patterns detected
dist/amd/handlebars/helpers/lookup.js safe No malicious patterns detected; this is a standard Handlebars lookup helper that delegates property access to options.lookupProperty.
dist/amd/handlebars/helpers/with.js safe This is a standard Handlebars template helper for the 'with' block, with no malicious patterns detected.
Show 72 more files
FileVerdictWhat the reviewer saw
dist/amd/handlebars/internal/proto-access.js safe No malicious patterns detected; the code implements a prototype access control mechanism for Handlebars templates.
dist/amd/handlebars/internal/wrapHelper.js safe This is a benign Handlebars helper wrapper that only transforms an options object and calls the wrapped helper; no malicious patterns detected.
dist/amd/handlebars/logger.js safe No malicious patterns detected; the file is a legitimate Handlebars logging utility that only calls console methods with no external data transmission, credential access, dynamic code execution, or file system/process manipulation.
dist/amd/handlebars/no-conflict.js safe This is the legitimate Handlebars 'noConflict' module; the only noteworthy pattern is a standard, self-cleaning globalThis polyfill, with no signs of malicious behavior.
dist/amd/handlebars/runtime.js safe This is the legitimate Handlebars runtime library with no malicious patterns detected.
dist/amd/handlebars/safe-string.js safe No malicious patterns detected
dist/amd/handlebars/utils.js safe No malicious patterns detected; the code contains standard Handlebars utility functions including HTML escaping, object extension, and type checks.
dist/amd/precompiler.js safe No malicious patterns detected; the Handlebars precompiler is a legitimate build tool with proper input sanitization and no signs of data exfiltration or code execution.
dist/cjs/handlebars.js safe This is a standard Handlebars.js module entry point with no malicious patterns, network activity, credential access, or dynamic code execution.
dist/cjs/handlebars.runtime.js safe No malicious patterns detected
dist/cjs/handlebars/base.js safe No malicious patterns detected; the file is a standard Handlebars runtime environment with only expected module imports and helper registration logic.
dist/cjs/handlebars/compiler/ast.js safe This file contains only pure AST helper functions for the Handlebars template compiler and uses no network, filesystem, process, or dynamic code execution primitives.
dist/cjs/handlebars/compiler/base.js safe No malicious patterns detected; the code performs Handlebars parsing with AST validation and contains no exfiltration, obfuscation, or dynamic execution.
dist/cjs/handlebars/compiler/code-gen.js safe No malicious patterns detected; the file contains only standard Handlebars code generation logic with a conditional require for the source-map library.
dist/cjs/handlebars/compiler/compiler.js safe No malicious patterns detected; this is the standard Handlebars compiler front-end with no network, filesystem, or process execution behavior.
dist/cjs/handlebars/compiler/helpers.js safe No malicious patterns detected; this is a standard Handlebars compiler helper module with no network, filesystem, process, or dynamic code execution activity.
dist/cjs/handlebars/compiler/printer.js safe This is a standard Handlebars AST printer with no malicious patterns; it only traverses and formats template AST nodes.
dist/cjs/handlebars/compiler/visitor.js safe This is a standard Handlebars AST visitor implementation with no malicious patterns, network activity, or suspicious behavior.
dist/cjs/handlebars/compiler/whitespace-control.js safe No malicious patterns detected; the file is legitimate Handlebars whitespace-control compiler logic with only a standard source map comment.
dist/cjs/handlebars/decorators.js safe No malicious patterns detected; the file is a standard Handlebars decorator registration module with a benign inline source map.
dist/cjs/handlebars/decorators/inline.js safe The file implements Handlebars' built-in 'inline' decorator functionality with no malicious patterns, external I/O, or dynamic code execution.
dist/cjs/handlebars/exception.js safe No malicious patterns detected; this is a legitimate Handlebars error exception class with no network, filesystem, process, or dynamic execution behavior.
dist/cjs/handlebars/helpers.js safe No malicious patterns detected in the analyzed Handlebars helper registration code.
dist/cjs/handlebars/helpers/block-helper-missing.js safe The code is a legitimate Handlebars helper implementation with no malicious patterns, external requests, or dynamic execution.
dist/cjs/handlebars/helpers/each.js safe No malicious patterns detected; this is a standard Handlebars 'each' helper implementation with no network, filesystem, process, or obfuscation concerns.
dist/cjs/handlebars/helpers/helper-missing.js safe No malicious patterns detected; the code only registers a standard Handlebars 'helperMissing' helper and throws a descriptive error for missing helpers.
dist/cjs/handlebars/helpers/if.js safe No malicious patterns detected; this is a legitimate Handlebars.js built-in 'if' and 'unless' helper implementation.
dist/cjs/handlebars/helpers/log.js safe No malicious patterns detected
dist/cjs/handlebars/helpers/lookup.js safe No malicious patterns detected; this is a legitimate Handlebars lookup helper implementation with no security concerns.
dist/cjs/handlebars/helpers/with.js safe No malicious patterns detected; this is a legitimate Handlebars helper implementation for the 'with' block helper.
dist/cjs/handlebars/internal/proto-access.js safe No malicious patterns detected in this Handlebars prototype access control module.
dist/cjs/handlebars/internal/wrapHelper.js safe No malicious patterns detected
dist/cjs/handlebars/logger.js safe No malicious patterns detected; the file implements a standard logging utility with no exfiltration, obfuscation, dynamic execution, or suspicious behavior.
dist/cjs/handlebars/no-conflict.js safe This is a legitimate noConflict helper for Handlebars that includes a standard, self-cleaning globalThis polyfill with no malicious behavior.
dist/cjs/handlebars/runtime.js safe No malicious patterns detected; the code is the standard Handlebars runtime with expected dynamic partial compilation behavior.
dist/cjs/handlebars/safe-string.js safe No malicious patterns detected; the file defines a basic SafeString type for Handlebars without any external calls, code execution, or suspicious behavior.
dist/cjs/handlebars/utils.js safe No malicious patterns detected; the file contains standard Handlebars utility functions for escaping, extending objects, and array/type checks with no network, filesystem, process, or dynamic code execution behavior.
dist/cjs/precompiler.js safe The file is a legitimate Handlebars precompiler with standard CLI file I/O and optional dependency loading, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscation, crypto mining, or backdoor installation.
dist/handlebars.runtime.js safe No malicious patterns detected in the Handlebars runtime bundle; it contains only standard template engine functionality with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process operations.
lib/.eslintrc.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars.js safe No malicious patterns detected; the code is a standard Handlebars runtime/compiler entry point with no exfiltration, credential harvesting, obfuscation, or suspicious execution behavior.
lib/handlebars.runtime.js safe No malicious patterns detected; this is a standard Handlebars runtime module initialization file.
lib/handlebars/base.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/compiler/ast.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/compiler/base.js safe No malicious patterns detected; the code is a standard Handlebars parser with input validation.
lib/handlebars/compiler/code-gen.js safe No malicious patterns detected; the conditional require of 'source-map' is a legitimate compiler dependency used for source map generation.
lib/handlebars/compiler/compiler.js safe No malicious patterns detected in the Handlebars compiler source file; it contains legitimate template compilation logic without exfiltration, credential harvesting, dynamic execution, or other red flags.
lib/handlebars/compiler/helpers.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/compiler/parser.js safe This is a Jison-generated Handlebars parser and lexer with no malicious patterns, data exfiltration, dynamic code execution, or suspicious behavior detected.
lib/handlebars/compiler/printer.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/compiler/visitor.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/compiler/whitespace-control.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/decorators.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/decorators/inline.js safe No malicious patterns detected; the code is a standard Handlebars inline decorator implementation with no external I/O, eval, process spawning, or credential access.
lib/handlebars/exception.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers/block-helper-missing.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers/each.js safe No malicious patterns detected
lib/handlebars/helpers/helper-missing.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers/if.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers/log.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers/lookup.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/helpers/with.js safe No malicious patterns detected; this is a legitimate Handlebars template helper implementation with no network, filesystem, process, or dynamic code execution activity.
lib/handlebars/internal/proto-access.js safe No malicious patterns detected; this is a legitimate Handlebars security module that controls prototype property access to prevent prototype pollution attacks.
lib/handlebars/internal/wrapHelper.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/logger.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/no-conflict.js safe The code is a legitimate Handlebars no-conflict utility that only manipulates the global namespace and contains no malicious patterns.
lib/handlebars/runtime.js safe No malicious patterns detected; this is the legitimate Handlebars runtime library with standard template rendering logic and no dynamic code execution, network, filesystem, or credential access.
lib/handlebars/safe-string.js safe Cleared by Jev triage; no further analysis needed
lib/handlebars/utils.js safe Cleared by Jev triage; no further analysis needed
lib/precompiler.js safe No malicious patterns detected; the code is the standard Handlebars precompiler with proper input sanitization and no exfiltration, execution, or filesystem abuse beyond expected template loading.
runtime.js safe No malicious patterns detected

Affected version ranges

None of the 2 scanned versions of handlebars are flagged high or critical. The latest scanned version, 4.7.9, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

4.7.84.7.9
VersionsVerdictCountRangeTop findings
4.7.9 Needs review 1 4.7.9 Dynamic code execution; Potential template/helper resolution issue
4.7.8 No issues 1 4.7.8

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of handlebars

VersionVerdictFilesScanned
4.7.9 Needs review 97 Oct 6, 2026
4.7.8 No issues 100 May 15, 2026

Frequently asked questions

Is handlebars safe to use?

No confirmed malware was found in handlebars@4.7.9, but the review flagged 3 medium, 11 low severity findings for risky patterns worth checking before you rely on it.

Does handlebars contain malware?

No malware was identified in handlebars@4.7.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was handlebars checked?

Togoder Security downloaded the published npm package and had an AI model read its 97 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan handlebars together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in handlebars@4.7.9, cost nothing.

Related security reports