Summary
Togoder Security scanned the npm package libnpmpack@9.1.12 on Oct 6, 2026. An AI review of 1 source file produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Lifecycle Script Execution
NPS-7B1424259FC5
The code executes package lifecycle scripts ('prepack' and 'postpack') via @npmcli/run-script when packing a directory. While this is standard npm behavior for npm pack, in a third-party package this can execute arbitrary code from a target package's package.json. If invoked on untrusted input (e.g., an attacker-controlled directory or package spec), it could lead to arbitrary command execution.
Lifecycle Script Execution
NPS-B9526BF45F39
The code runs the 'postpack' script with environment variables derived from the tarball, again via @npmcli/run-script. This is expected behavior for an npm pack utility but represents a code-execution surface.
Network Fetch via pacote
NPS-E6DE3BC05A95
Uses pacote.manifest and pacote.tarball to fetch manifests/tarballs from network registries based on the provided spec. This is inherent to the package manager function and expected, but means the module will perform outbound network requests based on input spec.
Filesystem Write
NPS-883169093C56
Writes the packed tarball to a destination resolved from opts.packDestination. Destination path is user-controlled via opts, which is normal CLI behavior but should be validated to avoid unintended writes (e.g., path traversal if a malicious caller controls packDestination).
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/index.js | medium | This appears to be a legitimate npm pack utility (functionally similar to npm pack) that fetches manifests/tarballs and runs standard prepack/postpack lifecycle scripts; no malicious exfiltration, credential harvesting, obfuscation, or backdoor patterns were detected, though lifecycle script execution and network fetches are inherent risks to be aware of. |
Scanned versions of libnpmpack
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 9.1.12 | Needs review | 1 | Oct 6, 2026 |
Frequently asked questions
Is libnpmpack safe to use?
No confirmed malware was found in libnpmpack@9.1.12, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does libnpmpack contain malware?
No malware was identified in libnpmpack@9.1.12 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was libnpmpack checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan libnpmpack together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in libnpmpack@9.1.12, cost nothing.