Togoder security

npm package security report

libnpmexec npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 10.3.2 Files reviewed 8 Size 20.9 KB Scanned

Summary

Togoder Security scanned the npm package libnpmexec@10.3.2 on Oct 6, 2026. An AI review of 8 source files produced 2 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
4
low

Findings 6

medium

Command injection potential

NPS-DF62BC58CD52

The args array is passed to runScript and executed as a shell command. Although there is an attempt to escape the executable path on non-Windows systems by single-quoting, the remaining args are passed without sanitization, which could lead to command injection if untrusted input reaches this function.

lib/run-script.js:21
medium

Shell command execution

NPS-0CFB98E6E394

The code uses @npmcli/run-script to execute arbitrary shell commands. While this is the intended purpose of the npx command, it represents a process spawning capability that could be abused if the module is compromised or if arguments are not properly sanitized.

lib/run-script.js:62
low

Environment variable and credential access

NPS-9B4120BB59C1

The code loads package.json and flatOptions which may contain environment variables, registry credentials, and other sensitive configuration. This is normal for npm CLI tools but represents access to potentially sensitive data.

lib/run-script.js:38
low

file system manipulation

NPS-5E6AE30EBCE3

Uses fs.utimes to touch lock files for liveness detection. This is a normal part of lock maintenance.

lib/with-lock.js
low

file system manipulation

NPS-DF35791A8667

Creates and removes lock directories (mkdir, rmdirSync) at user-provided lockPath. This is intended behavior for a lockfile library and does not indicate exfiltration or malicious activity.

lib/with-lock.js:48
low

timing/race condition

NPS-B4A9BD8C53AB

Stale lock detection and removal have a small window where another process could also delete and recreate the lock; the code acknowledges and attempts to detect this via inode/mtime checks.

lib/with-lock.js:62

Files reviewed

FileVerdictWhat the reviewer saw
lib/run-script.js medium This is legitimate npm CLI code for running npx scripts, but it executes arbitrary shell commands with potential command injection risks if untrusted input is passed as arguments.
lib/file-exists.js safe The code is a straightforward utility for locating local binaries in node_modules/.bin directories, using only filesystem stat checks with no network, process execution, or obfuscated behavior.
lib/get-bin-from-manifest.js safe Cleared by Jev triage; no further analysis needed
lib/index.js safe This is the legitimate npm exec implementation that resolves and runs packages without any malicious patterns such as data exfiltration, credential theft, or backdoors.
lib/is-windows.js safe Cleared by Jev triage; no further analysis needed
lib/no-tty.js safe Cleared by Jev triage; no further analysis needed
lib/strict-allow-scripts-preflight.js safe No malicious patterns detected
lib/with-lock.js safe The code implements a standard advisory lockfile mechanism with no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious patterns.

Scanned versions of libnpmexec

VersionVerdictFilesScanned
10.3.2 Needs review 8 Oct 6, 2026

Frequently asked questions

Is libnpmexec safe to use?

No confirmed malware was found in libnpmexec@10.3.2, but the review flagged 2 medium, 4 low severity findings for risky patterns worth checking before you rely on it.

Does libnpmexec contain malware?

No malware was identified in libnpmexec@10.3.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was libnpmexec checked?

Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan libnpmexec together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in libnpmexec@10.3.2, cost nothing.

Related security reports