Togoder security

npm package security report

json5 npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.2.3 Files reviewed 11 Size 180.5 KB Scanned

Summary

Togoder Security scanned the npm package json5@2.2.3 on Oct 6, 2026. An AI review of 11 source files produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
2
low

Findings 5

medium

import-time-side-effects

NPS-07AD84D0F3DA

The module executes significant top-level logic on import: it builds shared keys on the global object (__core-js_shared__), patches Function.prototype.toString with a fake implementation, and installs polyfills onto global/core prototypes. This runs automatically without any explicit invocation and modifies the host environment, which is an install/import-time behavior that should be reviewed.

dist/index.js:130
medium

builtin-prototype-tampering

NPS-2F27B1489FFA

_redefine replaces Function.prototype.toString with a wrapper that returns a stored source string instead of the real function source, potentially masking function contents. While intended for the core-js polyfill, prototype tampering of this kind can be abused for evasion and is a notable security-relevant pattern.

dist/index.js:190
medium

global-scope-modification

NPS-A063A94AB0F8

The bundled code actively writes to the global object (_global.core = _core and _redefine(Function.prototype, 'toString', ...)), patching Function.prototype.toString at runtime. Modifying built-in prototypes and global namespaces is a risky side effect that runs at import time and can interfere with other libraries or hide native behavior (anti-debugging/anti-detection technique).

dist/index.js:200
low

dynamic-code-execution

NPS-815B91231E06

The code uses Function('return this')() to obtain a global object reference (fallback for detecting the global scope). This is a form of dynamic code generation (equivalent to eval for this use case) and is a known pattern in core-js/JSON5 bundle output. Although used here for legitimate global detection, it demonstrates presence of dynamic execution primitives that could be abused or flagged by restrictive CSP policies.

dist/index.js:17
low

Deprecation Warning

NPS-1A8B21E669A8

This file simply loads a sibling module and prints a deprecation notice. It contains no malicious patterns.

lib/require.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.js medium This appears to be a legitimate bundled JSON5 parser (with an embedded core-js polyfill), but it contains several risk-relevant patterns including dynamic Function() execution, global namespace pollution, runtime patching of Function.prototype.toString, and import-time side effects.
dist/index.min.mjs safe No malicious patterns detected; the code is a legitimate JSON5 parser/serializer implementation with standard Unicode character class regexes and no network, file system, process, or dynamic code execution behavior.
dist/index.mjs safe No malicious patterns detected; the code is a standard JSON5 parser/serializer with Unicode regex tables and no network, filesystem, or process execution behavior.
lib/cli.js safe No malicious patterns detected; the CLI reads input, parses JSON5, and writes output as expected with no external network, credential, or process spawning behavior.
lib/index.js safe Cleared by Jev triage; no further analysis needed
lib/parse.js safe No malicious patterns detected; the file is a standard JSON5 parser implementation with no network, filesystem, process execution, or obfuscated code.
lib/register.js safe No malicious patterns detected
lib/require.js safe No malicious patterns detected; the file only provides backward-compatible module loading with a deprecation warning.
lib/stringify.js safe Cleared by Jev triage; no further analysis needed
lib/unicode.js safe This file only exports static Unicode regular expression character classes and contains no malicious patterns.
lib/util.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of json5 are flagged high or critical. The latest scanned version, 2.2.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.0.22.2.3
VersionsVerdictCountRangeTop findings
1.0.2 โ€“ 2.2.3 Needs review 2 >=1.0.2 <=2.2.3 global-scope-modification; import-time-side-effects

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of json5

VersionVerdictFilesScanned
2.2.3 Needs review 11 Oct 6, 2026
1.0.2 Needs review 9 Oct 6, 2026

Frequently asked questions

Is json5 safe to use?

No confirmed malware was found in json5@2.2.3, but the review flagged 3 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does json5 contain malware?

No malware was identified in json5@2.2.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was json5 checked?

Togoder Security downloaded the published npm package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan json5 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in json5@2.2.3, cost nothing.

Related security reports