Togoder security

npm package security report

hermes-parser@0.25.1 security report

No malicious code found.

No issues Version 0.25.1 Files reviewed 22 Size 858.0 KB Scanned

Summary

Togoder Security scanned the npm package hermes-parser@0.25.1 on Oct 6, 2026. An AI review of 22 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

Dynamic WASM loading

NPS-0D34E9ED6696

The code initializes a WebAssembly module (HermesParserWASM) and uses emscripten cwrap bindings for parsing. While dynamic code execution via WASM is present, it is a legitimate parser implementation, not obfuscated malware. The WASM module is imported from a relative file (./HermesParserWASM).

dist/HermesParser.js:45
low

Memory manipulation

NPS-4456BAC11492

Uses _malloc and _free to allocate/free WASM heap memory for source text. This is normal for WASM interop and does not involve file system or process manipulation.

dist/HermesParser.js:87

Files reviewed

FileVerdictWhat the reviewer saw
dist/HermesASTAdapter.js safe No malicious patterns detected; the code is a clean AST transformation adapter with no network, filesystem, process, or dynamic execution behavior.
dist/HermesParser.js safe The code is a legitimate JavaScript parser wrapper around a Hermes WASM module, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning.
dist/HermesParserDecodeUTF8String.js safe No malicious patterns detected; the code is a straightforward UTF-8 string decoder with no network, filesystem, process, or dynamic execution behavior.
dist/HermesParserDeserializer.js safe No malicious patterns detected
dist/HermesParserNodeDeserializers.js safe This generated AST deserializer file contains only pure data transformation functions with no network, filesystem, process, or dynamic code execution patterns.
dist/HermesToESTreeAdapter.js safe No malicious patterns detected in this AST adapter code; it performs pure AST transformations without network, filesystem, process, or dynamic code execution.
dist/ParserOptions.js safe No malicious patterns detected
dist/babel/TransformESTreeToBabel.js safe This file is a standard AST transformer from Meta's Hermes parser that converts ESTree to Babel AST format without any suspicious or malicious behavior.
dist/estree/StripComponentSyntax.js safe This is a legitimate Flow-to-ESTree AST transform from Meta's Flow toolchain that performs only pure syntax tree manipulation with no I/O, network, process, or dynamic code execution.
dist/estree/StripFlowTypes.js safe No malicious patterns detected; the code is a benign AST transform that strips Flow type annotations.
dist/estree/StripFlowTypesForBabel.js safe No malicious patterns detected
dist/generated/ESTreeVisitorKeys.js safe No malicious patterns detected
dist/generated/ParserVisitorKeys.js safe This generated file contains only a static data structure of AST visitor keys and exports constants, with no executable logic or malicious patterns.
dist/getModuleDocblock.js safe No malicious patterns detected; code only parses docblock comments and directives from a provided AST without network, filesystem, process, or dynamic execution behavior.
dist/index.js safe No malicious patterns detected
dist/transform/SimpleTransform.js safe No malicious patterns detected; the file is a legitimate AST transformation utility with no network, filesystem, process, or dynamic execution activity.
dist/transform/astArrayMutationHelpers.js safe No malicious patterns detected; the file contains only pure array manipulation utility functions with bounds checking and no network, filesystem, process, or dynamic code execution behavior.
dist/transform/astNodeMutationHelpers.js safe No malicious patterns detected; the file contains benign AST mutation helper functions with no network, filesystem, process execution, or obfuscated code.
dist/traverse/SimpleTraverser.js safe No malicious patterns detected
dist/traverse/getVisitorKeys.js safe No malicious patterns detected; the code only provides visitor key lookup utilities for an AST traversal library.
dist/utils/createSyntaxError.js safe No malicious patterns detected
dist/utils/mutateESTreeASTForPrettier.js safe No malicious patterns detected; the code is a legitimate AST transformation utility for Prettier compatibility in Flow/Hermes tooling with no network, filesystem, process, or dynamic execution behavior.

Frequently asked questions

Is hermes-parser safe to use?

Our AI source review of hermes-parser@0.25.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does hermes-parser contain malware?

No malware was identified in hermes-parser@0.25.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was hermes-parser checked?

Togoder Security downloaded the published npm package and had an AI model read its 22 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan hermes-parser together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in hermes-parser@0.25.1, cost nothing.

Related security reports