Summary
Togoder Security scanned the npm package libnpmexec@10.3.2 on Oct 6, 2026. An AI review of 8 source files produced 2 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
Command injection potential
NPS-DF62BC58CD52
The args array is passed to runScript and executed as a shell command. Although there is an attempt to escape the executable path on non-Windows systems by single-quoting, the remaining args are passed without sanitization, which could lead to command injection if untrusted input reaches this function.
Shell command execution
NPS-0CFB98E6E394
The code uses @npmcli/run-script to execute arbitrary shell commands. While this is the intended purpose of the npx command, it represents a process spawning capability that could be abused if the module is compromised or if arguments are not properly sanitized.
Environment variable and credential access
NPS-9B4120BB59C1
The code loads package.json and flatOptions which may contain environment variables, registry credentials, and other sensitive configuration. This is normal for npm CLI tools but represents access to potentially sensitive data.
file system manipulation
NPS-5E6AE30EBCE3
Uses fs.utimes to touch lock files for liveness detection. This is a normal part of lock maintenance.
file system manipulation
NPS-DF35791A8667
Creates and removes lock directories (mkdir, rmdirSync) at user-provided lockPath. This is intended behavior for a lockfile library and does not indicate exfiltration or malicious activity.
timing/race condition
NPS-B4A9BD8C53AB
Stale lock detection and removal have a small window where another process could also delete and recreate the lock; the code acknowledges and attempts to detect this via inode/mtime checks.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/run-script.js | medium | This is legitimate npm CLI code for running npx scripts, but it executes arbitrary shell commands with potential command injection risks if untrusted input is passed as arguments. |
| lib/file-exists.js | safe | The code is a straightforward utility for locating local binaries in node_modules/.bin directories, using only filesystem stat checks with no network, process execution, or obfuscated behavior. |
| lib/get-bin-from-manifest.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | This is the legitimate npm exec implementation that resolves and runs packages without any malicious patterns such as data exfiltration, credential theft, or backdoors. |
| lib/is-windows.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/no-tty.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/strict-allow-scripts-preflight.js | safe | No malicious patterns detected |
| lib/with-lock.js | safe | The code implements a standard advisory lockfile mechanism with no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious patterns. |
Scanned versions of libnpmexec
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 10.3.2 | Needs review | 8 | Oct 6, 2026 |
Frequently asked questions
Is libnpmexec safe to use?
No confirmed malware was found in libnpmexec@10.3.2, but the review flagged 2 medium, 4 low severity findings for risky patterns worth checking before you rely on it.
Does libnpmexec contain malware?
No malware was identified in libnpmexec@10.3.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was libnpmexec checked?
Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan libnpmexec together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in libnpmexec@10.3.2, cost nothing.