Summary
Togoder Security scanned the npm package marked@15.0.12 on Oct 6, 2026. An AI review of 5 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic code execution via config file loading
NPS-2E745A1D842B
The runConfig function dynamically loads and executes arbitrary JavaScript/JSON config files specified by the user via --config or default locations like ~/.marked.json, ~/.marked.js, and ~/.marked/index.js. It uses require(configFile) or import('file:///' + configFile), which can execute arbitrary code if an attacker can place a malicious file in one of these locations or trick the user into using a malicious config. While this is a legitimate feature, it represents a potential security risk if untrusted config files are used.
Spawning external process
NPS-7220B8A27246
The help function spawns the man command to display manual pages. This is expected behavior for a CLI tool and does not appear malicious, but it is a process spawn that could be abused if the environment is compromised (e.g., PATH manipulation).
File system access outside package scope
NPS-4674AF817484
The code reads and writes files based on user input and default config paths, including home directory files. This is typical for a CLI tool but could be used to read/write arbitrary files if an attacker controls arguments. No evidence of malicious intent.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bin/main.js | medium | The code is a legitimate Markdown CLI tool but includes dynamic config loading that could execute arbitrary code, posing a medium risk if untrusted configs are used. |
| bin/marked.js | safe | No malicious patterns detected; the file is a simple CLI entry point that sets a process title and invokes the package's main function. |
| lib/marked.cjs | safe | No malicious patterns detected; this is a legitimate generated build of the marked markdown parser, containing only parser logic with no network, filesystem, process, credential-harvesting, or dynamic code execution behavior. |
| lib/marked.esm.js | safe | This is the well-known marked Markdown parser library (v15.0.12, MIT licensed); it contains only markdown parsing/rendering logic, uses no network, filesystem, process-execution, eval, or obfuscated code, and exhibits no malicious patterns. |
| lib/marked.umd.js | safe | No malicious patterns detected in the marked library UMD bundle; it is a standard markdown parser with no exfiltration, code execution, or install-time hooks. |
Scanned versions of marked
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 15.0.12 | Needs review | 5 | Oct 6, 2026 |
Frequently asked questions
Is marked safe to use?
No confirmed malware was found in marked@15.0.12, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does marked contain malware?
No malware was identified in marked@15.0.12 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was marked checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan marked together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in marked@15.0.12, cost nothing.