Summary
Togoder Security scanned the npm package loose-envify@1.4.0 on Oct 4, 2026. An AI review of 5 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
environment variable harvesting
NPS-673E924B8E21
The module passes the entire process.env object into the loose-envify function. loose-envify is designed to replace process.env references with values from the provided environment object. While this is a legitimate and well-known package (used by browserify), passing the full environment allows any environment variables to potentially be exposed or transformed. This pattern is worth noting because environment variables can contain secrets, tokens, and credentials. If the dependency were replaced or compromised, it could access all environment variables.
dynamic module loading
NPS-F609436C688F
The code uses require('./loose-envify') to load a module that returns a function, which is then invoked with process.env. This is a common pattern but relies on a local file that was not included in the analysis. If the ./loose-envify file were malicious or tampered with, it could perform any operation with access to the full environment.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | No overtly malicious code, but the module passes the complete process environment into a dependency, which could expose sensitive variables if the dependency is compromised or malicious. |
| cli.js | safe | No malicious patterns detected |
| custom.js | safe | Cleared by Jev triage; no further analysis needed |
| loose-envify.js | safe | No malicious patterns detected; the code is a legitimate browserify transform that replaces environment variable references in JavaScript files. |
| replace.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of loose-envify
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.4.0 | Needs review | 5 | Oct 4, 2026 |
Frequently asked questions
Is loose-envify safe to use?
No confirmed malware was found in loose-envify@1.4.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does loose-envify contain malware?
No malware was identified in loose-envify@1.4.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was loose-envify checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan loose-envify together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in loose-envify@1.4.0, cost nothing.