Summary
Togoder Security scanned the npm package hermes-parser@0.25.1 on Oct 6, 2026. An AI review of 22 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
Dynamic WASM loading
NPS-0D34E9ED6696
The code initializes a WebAssembly module (HermesParserWASM) and uses emscripten cwrap bindings for parsing. While dynamic code execution via WASM is present, it is a legitimate parser implementation, not obfuscated malware. The WASM module is imported from a relative file (./HermesParserWASM).
Memory manipulation
NPS-4456BAC11492
Uses _malloc and _free to allocate/free WASM heap memory for source text. This is normal for WASM interop and does not involve file system or process manipulation.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/HermesASTAdapter.js | safe | No malicious patterns detected; the code is a clean AST transformation adapter with no network, filesystem, process, or dynamic execution behavior. |
| dist/HermesParser.js | safe | The code is a legitimate JavaScript parser wrapper around a Hermes WASM module, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/HermesParserDecodeUTF8String.js | safe | No malicious patterns detected; the code is a straightforward UTF-8 string decoder with no network, filesystem, process, or dynamic execution behavior. |
| dist/HermesParserDeserializer.js | safe | No malicious patterns detected |
| dist/HermesParserNodeDeserializers.js | safe | This generated AST deserializer file contains only pure data transformation functions with no network, filesystem, process, or dynamic code execution patterns. |
| dist/HermesToESTreeAdapter.js | safe | No malicious patterns detected in this AST adapter code; it performs pure AST transformations without network, filesystem, process, or dynamic code execution. |
| dist/ParserOptions.js | safe | No malicious patterns detected |
| dist/babel/TransformESTreeToBabel.js | safe | This file is a standard AST transformer from Meta's Hermes parser that converts ESTree to Babel AST format without any suspicious or malicious behavior. |
| dist/estree/StripComponentSyntax.js | safe | This is a legitimate Flow-to-ESTree AST transform from Meta's Flow toolchain that performs only pure syntax tree manipulation with no I/O, network, process, or dynamic code execution. |
| dist/estree/StripFlowTypes.js | safe | No malicious patterns detected; the code is a benign AST transform that strips Flow type annotations. |
| dist/estree/StripFlowTypesForBabel.js | safe | No malicious patterns detected |
| dist/generated/ESTreeVisitorKeys.js | safe | No malicious patterns detected |
| dist/generated/ParserVisitorKeys.js | safe | This generated file contains only a static data structure of AST visitor keys and exports constants, with no executable logic or malicious patterns. |
| dist/getModuleDocblock.js | safe | No malicious patterns detected; code only parses docblock comments and directives from a provided AST without network, filesystem, process, or dynamic execution behavior. |
| dist/index.js | safe | No malicious patterns detected |
| dist/transform/SimpleTransform.js | safe | No malicious patterns detected; the file is a legitimate AST transformation utility with no network, filesystem, process, or dynamic execution activity. |
| dist/transform/astArrayMutationHelpers.js | safe | No malicious patterns detected; the file contains only pure array manipulation utility functions with bounds checking and no network, filesystem, process, or dynamic code execution behavior. |
| dist/transform/astNodeMutationHelpers.js | safe | No malicious patterns detected; the file contains benign AST mutation helper functions with no network, filesystem, process execution, or obfuscated code. |
| dist/traverse/SimpleTraverser.js | safe | No malicious patterns detected |
| dist/traverse/getVisitorKeys.js | safe | No malicious patterns detected; the code only provides visitor key lookup utilities for an AST traversal library. |
| dist/utils/createSyntaxError.js | safe | No malicious patterns detected |
| dist/utils/mutateESTreeASTForPrettier.js | safe | No malicious patterns detected; the code is a legitimate AST transformation utility for Prettier compatibility in Flow/Hermes tooling with no network, filesystem, process, or dynamic execution behavior. |
Scanned versions of hermes-parser
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 0.25.1 | No issues | 22 | Oct 6, 2026 |
Frequently asked questions
Is hermes-parser safe to use?
Our AI source review of hermes-parser@0.25.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does hermes-parser contain malware?
No malware was identified in hermes-parser@0.25.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was hermes-parser checked?
Togoder Security downloaded the published npm package and had an AI model read its 22 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan hermes-parser together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in hermes-parser@0.25.1, cost nothing.