Summary
Togoder Security scanned the npm package libnpmversion@8.0.4 on Oct 6, 2026. An AI review of 8 source files produced 4 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
Potential argument injection
NPS-F3993C267442
The tag value is built by concatenating tagVersionPrefix and version without validation. If version or tagVersionPrefix begins with -, it could be interpreted as a git option rather than a tag name, potentially allowing argument injection into the spawned git command.
Process spawning / shell command execution
NPS-C82272DCE784
The module invokes git.spawn(...) from @npmcli/git, which spawns a child process to run the git tag command. Although the arguments are passed as an array (not a shell string), this is still external process execution and is a potential attack surface if inputs like tag, message, or opts are influenced by untrusted sources.
Arbitrary script execution
NPS-A85A2E3366EE
The module calls runScript (from @npmcli/run-script) to execute package lifecycle scripts ('preversion', 'version', 'postversion'). This is by design for npm versioning, but it means arbitrary code from package.json scripts will be executed. If a malicious package.json is processed, this could lead to code execution.
File system manipulation
NPS-494AF256E0E7
The module writes to package.json, package-lock.json, and npm-shrinkwrap.json on disk. Modifying package.json via writeJson could be abused if 'pkg' object is influenced by untrusted input, potentially injecting malicious scripts or dependencies into the package.json.
User-controlled message interpolation
NPS-061B20D1891B
message.replace(/%s/g, version) interpolates the supplied version into a git tag message. Combined with -m in the flags, an attacker-controlled message could potentially alter git behavior or inject unexpected content, depending on how @npmcli/git constructs and escapes arguments.
Spawning processes / shell commands
NPS-FD3DC641AB1F
The module uses git.spawn (from @npmcli/git) to execute git commands such as 'git add', 'git commit', and 'git tag'. While these are expected operations for a versioning tool, spawning external processes introduces risk if arguments are user-controlled or if the git binary is hijacked.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/tag.js | medium | The file is likely part of a legitimate npm versioning workflow, but it spawns git processes with user-influenced arguments and lacks validation, creating argument-injection and command-execution risk if inputs are untrusted. |
| lib/version.js | medium | The code performs expected npm versioning operations but uses script execution and process spawning that could be risky if inputs are untrusted. |
| lib/commit.js | safe | No malicious patterns detected |
| lib/enforce-clean.js | safe | No malicious patterns detected |
| lib/index.js | safe | No malicious patterns detected |
| lib/read-json.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/retrieve-tag.js | safe | The code uses @npmcli/git to run git describe and semver to parse the tag; no malicious patterns or security concerns were detected. |
| lib/write-json.js | safe | No malicious patterns detected; the code only serializes a package.json object and writes it back to disk using standard Node.js APIs. |
Scanned versions of libnpmversion
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 8.0.4 | Needs review | 8 | Oct 6, 2026 |
Frequently asked questions
Is libnpmversion safe to use?
No confirmed malware was found in libnpmversion@8.0.4, but the review flagged 4 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does libnpmversion contain malware?
No malware was identified in libnpmversion@8.0.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was libnpmversion checked?
Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan libnpmversion together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in libnpmversion@8.0.4, cost nothing.