# json5@2.2.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:10:42.000Z
- Files reviewed: 11
- Findings: 3 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/json5@2.2.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package json5@2.2.3 on Oct 6, 2026. An AI review of 11 source files produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] import-time-side-effects

Finding ID: `NPS-07AD84D0F3DA`

File: `dist/index.js:130`

The module executes significant top-level logic on import: it builds shared keys on the global object (`__core-js_shared__`), patches `Function.prototype.toString` with a fake implementation, and installs polyfills onto global/core prototypes. This runs automatically without any explicit invocation and modifies the host environment, which is an install/import-time behavior that should be reviewed.

### [medium] builtin-prototype-tampering

Finding ID: `NPS-2F27B1489FFA`

File: `dist/index.js:190`

`_redefine` replaces `Function.prototype.toString` with a wrapper that returns a stored source string instead of the real function source, potentially masking function contents. While intended for the core-js polyfill, prototype tampering of this kind can be abused for evasion and is a notable security-relevant pattern.

### [medium] global-scope-modification

Finding ID: `NPS-A063A94AB0F8`

File: `dist/index.js:200`

The bundled code actively writes to the global object (`_global.core = _core` and `_redefine(Function.prototype, 'toString', ...)`), patching `Function.prototype.toString` at runtime. Modifying built-in prototypes and global namespaces is a risky side effect that runs at import time and can interfere with other libraries or hide native behavior (anti-debugging/anti-detection technique).

### [low] dynamic-code-execution

Finding ID: `NPS-815B91231E06`

File: `dist/index.js:17`

The code uses `Function('return this')()` to obtain a global object reference (fallback for detecting the global scope). This is a form of dynamic code generation (equivalent to eval for this use case) and is a known pattern in core-js/JSON5 bundle output. Although used here for legitimate global detection, it demonstrates presence of dynamic execution primitives that could be abused or flagged by restrictive CSP policies.

### [low] Deprecation Warning

Finding ID: `NPS-1A8B21E669A8`

File: `lib/require.js`

This file simply loads a sibling module and prints a deprecation notice. It contains no malicious patterns.

## Files reviewed

- `dist/index.js` (medium): This appears to be a legitimate bundled JSON5 parser (with an embedded core-js polyfill), but it contains several risk-relevant patterns including dynamic Function() execution, global namespace pollution, runtime patching of Function.prototype.toString, and import-time side effects.
- `dist/index.min.mjs` (safe): No malicious patterns detected; the code is a legitimate JSON5 parser/serializer implementation with standard Unicode character class regexes and no network, file system, process, or dynamic code execution behavior.
- `dist/index.mjs` (safe): No malicious patterns detected; the code is a standard JSON5 parser/serializer with Unicode regex tables and no network, filesystem, or process execution behavior.
- `lib/cli.js` (safe): No malicious patterns detected; the CLI reads input, parses JSON5, and writes output as expected with no external network, credential, or process spawning behavior.
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parse.js` (safe): No malicious patterns detected; the file is a standard JSON5 parser implementation with no network, filesystem, process execution, or obfuscated code.
- `lib/register.js` (safe): No malicious patterns detected
- `lib/require.js` (safe): No malicious patterns detected; the file only provides backward-compatible module loading with a deprecation warning.
- `lib/stringify.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/unicode.js` (safe): This file only exports static Unicode regular expression character classes and contains no malicious patterns.
- `lib/util.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of json5 are flagged high or critical. The latest scanned version, 2.2.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.0.2 – 2.2.3 (`>=1.0.2 <=2.2.3`): medium (global-scope-modification +2 more)

## Scanned versions

- [2.2.3](https://security.togoder.click/npm/json5@2.2.3): medium, 2026-10-06T14:10:42.000Z
- [1.0.2](https://security.togoder.click/npm/json5@1.0.2): medium, 2026-10-06T14:17:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
