Summary
Togoder Security scanned the npm package json5@1.0.2 on Oct 6, 2026. An AI review of 9 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Module system modification
NPS-4CF863F164FA
Registers a custom require.extensions handler for .json5 files, modifying Node.js module loading behavior at import time. This is a common legitimate pattern for JSON5 parsers, but it changes global require behavior for any project using this package.
Top-level code execution
NPS-DC3B7478BD80
Code executes at import time (require.extensions assignment), altering the runtime environment of the host application. While typical for this library's purpose, it demonstrates import-time side effects.
File system read
NPS-1D444D3ECC13
Reads arbitrary .json5 files from disk via fs.readFileSync when such files are required. This is the expected behavior of a JSON5 parser module and stays within the scope requested by the consumer.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/register.js | medium | The code is a standard JSON5 require extension hook that modifies module loading and reads files as expected for this library, with no signs of exfiltration, credential harvesting, obfuscation, or malicious network/process activity. |
| dist/index.js | safe | The code is a legitimate implementation of the JSON5 parsing and stringifying library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or dynamic code execution. |
| lib/cli.js | safe | No malicious patterns detected; the code is a standard JSON5 CLI parser with no network, credential, or process execution behavior. |
| lib/index.js | safe | This is a standard compiled CommonJS module that re-exports parse and stringify functions, with no suspicious or malicious patterns detected. |
| lib/parse.js | safe | No malicious patterns detected; this is a legitimate JSON5 parser implementation. |
| lib/require.js | safe | No malicious patterns detected |
| lib/stringify.js | safe | This is a legitimate JSON5 stringify implementation with no malicious patterns detected; it only performs serialization and string manipulation with no network, filesystem, process, or dynamic execution activities. |
| lib/unicode.js | safe | No malicious patterns detected; the file contains only Unicode property escape regular expressions for identifier and whitespace matching, with no I/O, network, process execution, or obfuscated behavior. |
| lib/util.js | safe | No malicious patterns detected; the file contains only standard utility functions for character classification using Unicode regex tests. |
Affected version ranges
None of the 2 scanned versions of json5 are flagged high or critical. The latest scanned version, 2.2.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 1.0.2 โ 2.2.3 | Needs review | 2 | >=1.0.2 <=2.2.3 | global-scope-modification; import-time-side-effects |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of json5
Frequently asked questions
Is json5 safe to use?
No confirmed malware was found in json5@1.0.2, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does json5 contain malware?
No malware was identified in json5@1.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was json5 checked?
Togoder Security downloaded the published npm package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan json5 together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in json5@1.0.2, cost nothing.