Summary
Togoder Security scanned the npm package libnpmdiff@8.1.12 on Oct 6, 2026. An AI review of 5 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
path traversal / tar extraction
NPS-729F72441684
The untar function processes tar archives using the 'tar' package with a filter callback. It normalizes paths and constructs keys by stripping the first path segment. No extraction to disk is performed (only listing and reading entry contents into memory), and paths are normalized but not used for filesystem writes, so path traversal risk is low. However, reliance on external tar input without explicit validation is noted.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/format-diff.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | No malicious patterns detected; the code is a standard package diff utility using pacote for registry access and local helpers for diffing. |
| lib/should-print-patch.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/tarball.js | safe | No malicious patterns detected; the code is a benign npm tarball creation utility using official npm libraries. |
| lib/untar.js | safe | The file reads tar archive contents into memory using the tar package with path normalization; no data exfiltration, credential harvesting, obfuscation, process spawning, or malicious behavior was detected. |
Frequently asked questions
Is libnpmdiff safe to use?
Our AI source review of libnpmdiff@8.1.12 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does libnpmdiff contain malware?
No malware was identified in libnpmdiff@8.1.12 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was libnpmdiff checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan libnpmdiff together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in libnpmdiff@8.1.12, cost nothing.