# libnpmdiff@8.1.12 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:19.000Z
- Files reviewed: 5
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/libnpmdiff
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package libnpmdiff@8.1.12 on Oct 6, 2026. An AI review of 5 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] path traversal / tar extraction

Finding ID: `NPS-729F72441684`

File: `lib/untar.js`

The untar function processes tar archives using the 'tar' package with a filter callback. It normalizes paths and constructs keys by stripping the first path segment. No extraction to disk is performed (only listing and reading entry contents into memory), and paths are normalized but not used for filesystem writes, so path traversal risk is low. However, reliance on external tar input without explicit validation is noted.

## Files reviewed

- `lib/format-diff.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): No malicious patterns detected; the code is a standard package diff utility using pacote for registry access and local helpers for diffing.
- `lib/should-print-patch.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/tarball.js` (safe): No malicious patterns detected; the code is a benign npm tarball creation utility using official npm libraries.
- `lib/untar.js` (safe): The file reads tar archive contents into memory using the tar package with path normalization; no data exfiltration, credential harvesting, obfuscation, process spawning, or malicious behavior was detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
