# make-asynchronous@1.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:19:21.000Z
- Files reviewed: 1
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/make-asynchronous
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package make-asynchronous@1.0.1 on Oct 6, 2026. An AI review of 1 source file produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-8DA4D2121490`

File: `index.js:47`

The code serializes a user-provided function via function_.toString() and executes it inside a Web Worker using a data URL (Node) or blob URL (browser). This is dynamic code execution from a string, which could allow arbitrary code execution if the function argument is untrusted, though it is the intended behavior of this library.

### [medium] Dynamic code execution

Finding ID: `NPS-67513085A9FE`

File: `index.js:112`

Similar to makeContent, makeIterableContent serializes and executes a user-supplied function inside a worker via string concatenation into executable JavaScript.

### [low] Obfuscation / encoded payload

Finding ID: `NPS-7BD582C47930`

File: `index.js:9`

The makeDataUrl function base64-encodes JavaScript content to form a data URL worker. While this is a legitimate workaround for a known web-worker issue, base64-encoded dynamic script execution resembles obfuscation techniques often used to hide malicious payloads.

## Files reviewed

- `index.js` (medium): The package dynamically constructs and executes worker scripts from serialized user functions via data/blob URLs and base64 encoding, which is intentional functionality but presents code execution risks if input is untrusted; no exfiltration, credential harvesting, backdoors, or network calls to external hosts were detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
