Togoder security

npm package security report

husky npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 9.1.7 Files reviewed 2 Size 1.9 KB Scanned

Summary

Togoder Security scanned the npm package husky@9.1.7 on Oct 6, 2026. An AI review of 2 source files produced 4 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
3
low

Findings 7

medium

File system manipulation outside package scope

NPS-3B07F333436F

The 'init' command reads and rewrites the project's package.json, adding a 'prepare' script set to 'husky', and creates a .husky/pre-commit hook file. While this is consistent with husky's legitimate behavior, it modifies configuration and creates executable hook scripts in the user's project without explicit consent beyond running the command.

bin.js:12
medium

Arbitrary hook script creation

NPS-32049BAF875D

Writes a .husky/pre-commit file whose content is derived from the npm_config_user_agent environment variable and appends 'test\n'. This creates a git hook that runs on every commit. The content is not attacker-controlled here (derived from a well-known env var), but writing executable git hooks is a sensitive operation.

bin.js:16
medium

Install-time side effects

NPS-A1620A6D2026

Top-level/exported function performs filesystem writes (mkdirSync, writeFileSync, copyFileSync, rmSync) and runs a git command when invoked. If wired to a lifecycle script (e.g. prepare/postinstall), it executes at install time and can modify the consumer's git configuration.

index.js
medium

File system manipulation outside package scope

NPS-205DADBD9C0F

Writes git hook scripts and .gitignore files under the .husky directory and modifies git configuration (core.hooksPath). This modifies the host repository's git configuration and hook path, which affects behavior outside the package directory.

index.js:16
low

Environment variable access

NPS-16A64ECF6A87

Reads process.env.npm_config_user_agent to determine the package manager name. This is standard for CLI tools and not credential harvesting, but it is environment inspection.

bin.js:16
low

Deprecated command handling / process exit

NPS-63F32BF2A681

Commands 'add', 'set', 'uninstall', and 'install' are deprecated and cause the process to exit with error codes. Not malicious but changes behavior for callers.

bin.js:21
low

Process execution

NPS-83F0A659666B

Uses child_process.spawnSync to invoke 'git config core.hooksPath', a shell-adjacent process execution. This is expected behavior for a git hooks manager (husky), but still constitutes spawning a process.

index.js:18

Files reviewed

FileVerdictWhat the reviewer saw
bin.js medium The script implements husky's legitimate init/install workflow but writes git hooks and modifies package.json, which are sensitive operations typical of lifecycle tooling rather than clear malicious behavior.
index.js medium Code matches the legitimate 'husky' git hooks installer pattern: it configures core.hooksPath and writes hook scripts, with no evidence of exfiltration, credential harvesting, obfuscation, or backdoor behavior, though it does spawn git and modify repository configuration.

Scanned versions of husky

VersionVerdictFilesScanned
9.1.7 Needs review 2 Oct 6, 2026

Frequently asked questions

Is husky safe to use?

No confirmed malware was found in husky@9.1.7, but the review flagged 4 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does husky contain malware?

No malware was identified in husky@9.1.7 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was husky checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan husky together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in husky@9.1.7, cost nothing.

Related security reports