Summary
Togoder Security scanned the npm package lru-cache@11.5.3 on Oct 4, 2026. An AI review of 24 source files produced 16 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 16
process.emitWarning usage
NPS-A437F49CE21C
Uses process.emitWarning for deprecation/warning messages, which is a benign Node.js API. It checks for the existence of the method before calling it, avoiding errors in non-Node environments.
dynamic property access via unsafeExposeInternals
NPS-9742A1D76FD5
Static method unsafeExposeInternals(c) returns internal private fields for testing/debugging purposes. It explicitly warns that modifying returned objects may cause breakage. No external data is leaked or exfiltrated.
unref timers
NPS-67909FCCF4A4
Calls clearTimeout and setTimeout for TTL autopurge timers, and uses t.unref() to avoid keeping the Node.js event loop alive. This is standard practice for background timers and not malicious.
AbortController usage
NPS-45657845892B
Uses AbortController to cancel background fetch operations and propagate abort signals. This is a standard web/Node API for cancellation, not a security concern.
process.emitWarning usage
NPS-A437F49CE21C
Uses process.emitWarning for deprecation/warning messages, which is a benign Node.js API. It checks for the existence of the method before calling it, avoiding errors in non-Node environments.
dynamic property access via unsafeExposeInternals
NPS-9742A1D76FD5
Static method unsafeExposeInternals(c) returns internal private fields for testing/debugging purposes. It explicitly warns that modifying returned objects may cause breakage. No external data is leaked or exfiltrated.
unref timers
NPS-67909FCCF4A4
Calls clearTimeout and setTimeout for TTL autopurge timers, and uses t.unref() to avoid keeping the Node.js event loop alive. This is standard practice for background timers and not malicious.
AbortController usage
NPS-45657845892B
Uses AbortController to cancel background fetch operations and propagate abort signals. This is a standard web/Node API for cancellation, not a security concern.
process.emitWarning usage
NPS-A437F49CE21C
Uses process.emitWarning for deprecation/warning messages, which is a benign Node.js API. It checks for the existence of the method before calling it, avoiding errors in non-Node environments.
dynamic property access via unsafeExposeInternals
NPS-9742A1D76FD5
Static method unsafeExposeInternals(c) returns internal private fields for testing/debugging purposes. It explicitly warns that modifying returned objects may cause breakage. No external data is leaked or exfiltrated.
unref timers
NPS-67909FCCF4A4
Calls clearTimeout and setTimeout for TTL autopurge timers, and uses t.unref() to avoid keeping the Node.js event loop alive. This is standard practice for background timers and not malicious.
AbortController usage
NPS-45657845892B
Uses AbortController to cancel background fetch operations and propagate abort signals. This is a standard web/Node API for cancellation, not a security concern.
process.emitWarning usage
NPS-A437F49CE21C
Uses process.emitWarning for deprecation/warning messages, which is a benign Node.js API. It checks for the existence of the method before calling it, avoiding errors in non-Node environments.
dynamic property access via unsafeExposeInternals
NPS-9742A1D76FD5
Static method unsafeExposeInternals(c) returns internal private fields for testing/debugging purposes. It explicitly warns that modifying returned objects may cause breakage. No external data is leaked or exfiltrated.
unref timers
NPS-67909FCCF4A4
Calls clearTimeout and setTimeout for TTL autopurge timers, and uses t.unref() to avoid keeping the Node.js event loop alive. This is standard practice for background timers and not malicious.
AbortController usage
NPS-45657845892B
Uses AbortController to cancel background fetch operations and propagate abort signals. This is a standard web/Node API for cancellation, not a security concern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/commonjs/browser/diagnostics-channel.js | safe | No malicious patterns detected |
| dist/commonjs/browser/index.js | safe | No malicious patterns detected; this is a standard LRU cache implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/commonjs/browser/perf.js | safe | No malicious patterns detected; the code simply selects performance.now if available, otherwise falls back to Date. |
| dist/commonjs/diagnostics-channel.js | safe | No malicious patterns detected |
| dist/commonjs/index.js | safe | No malicious patterns detected; this is a standard LRU cache implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/commonjs/node/diagnostics-channel.js | safe | This file only imports Node.js built-in diagnostics_channel to expose metrics and tracing channels, with no malicious patterns detected. |
| dist/commonjs/node/index.js | safe | No malicious patterns detected; this is a standard LRU cache implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/commonjs/node/perf.js | safe | No malicious patterns detected; the code simply selects performance.now if available, otherwise falls back to Date. |
| dist/commonjs/perf.js | safe | No malicious patterns detected; the code simply selects performance.now if available, otherwise falls back to Date. |
| dist/commonjs/react-native/diagnostics-channel.js | safe | No malicious patterns detected |
| dist/commonjs/react-native/index.js | safe | No malicious patterns detected; this is a standard LRU cache implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/commonjs/react-native/perf.js | safe | No malicious patterns detected; the code simply selects performance.now if available, otherwise falls back to Date. |
| dist/esm/browser/diagnostics-channel.js | safe | No malicious patterns detected |
| dist/esm/browser/index.js | safe | The code implements an LRU cache with TTL and background fetch support; it contains no exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns. |
| dist/esm/browser/perf.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/diagnostics-channel.js | safe | This is a benign polyfill for node:diagnostics_channel that gracefully falls back to a no-op stub when the module is unavailable, with no malicious patterns detected. |
| dist/esm/index.js | safe | The code implements an LRU cache with TTL and background fetch support; it contains no exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns. |
| dist/esm/node/diagnostics-channel.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/node/index.js | safe | The code implements an LRU cache with TTL and background fetch support; it contains no exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns. |
| dist/esm/node/perf.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/perf.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/react-native/diagnostics-channel.js | safe | No malicious patterns detected |
| dist/esm/react-native/index.js | safe | The code implements an LRU cache with TTL and background fetch support; it contains no exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns. |
| dist/esm/react-native/perf.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 6 scanned versions of lru-cache are flagged high or critical. The latest scanned version, 11.5.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 11.2.6 – 11.5.3 | No issues | 3 | >=11.2.6 <=11.5.3 | |
| 11.2.5 | Not scanned | 1 | 11.2.5 | |
| 10.4.3 | No issues | 1 | 10.4.3 | |
| 7.18.3 | Not scanned | 1 | 7.18.3 | |
| 5.1.1 – 6.0.0 | No issues | 2 | >=5.1.1 <=6.0.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of lru-cache
Frequently asked questions
Is lru-cache safe to use?
Our AI source review of lru-cache@11.5.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does lru-cache contain malware?
No malware was identified in lru-cache@11.5.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was lru-cache checked?
Togoder Security downloaded the published npm package and had an AI model read its 24 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan lru-cache together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in lru-cache@11.5.3, cost nothing.