Summary
Togoder Security scanned the npm package minimatch@3.1.5 on Oct 6, 2026. An AI review of 1 source file produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Dynamic regular expression construction
NPS-7BA8CE8A487E
The code constructs regular expressions dynamically from user-supplied glob patterns. While this is inherent to the minimatch library's functionality, it can be a vector for ReDoS if not carefully bounded. The code includes a MAX_PATTERN_LENGTH check (1024*64) and a maxGlobstarRecursion limit (default 200) to mitigate this, but dynamic regex generation from external input remains a potential risk.
Use of new RegExp with user-controlled input
NPS-1E5EE6552445
Throughout the parse and makeRe functions, user-supplied patterns are converted into RegExp objects. Although the library escapes special characters and limits pattern length, any vulnerability in the regex engine or bypass of the escaping logic could lead to denial of service or unexpected matching behavior.
Environment-dependent path separator handling
NPS-DAEED8341CAD
The code conditionally requires the 'path' module and adjusts for Windows path separators. This is standard behavior for a cross-platform glob library and does not constitute a security concern by itself.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| minimatch.js | medium | The minimatch library is a legitimate glob matching utility with no evidence of malicious intent; it includes safeguards against ReDoS, though dynamic regex generation from user input is an inherent low-risk characteristic. |
Affected version ranges
None of the 3 scanned versions of minimatch are flagged high or critical. The latest scanned version, 10.2.6, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 10.2.5 – 10.2.6 | No issues | 2 | >=10.2.5 <=10.2.6 | |
| 5.1.9 – 10.2.4 | Not scanned | 6 | >=5.1.9 <=10.2.4 | |
| 3.1.5 | Needs review | 1 | 3.1.5 | |
| 3.1.2 – 3.1.4 | Not scanned | 2 | >=3.1.2 <=3.1.4 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of minimatch
Frequently asked questions
Is minimatch safe to use?
No confirmed malware was found in minimatch@3.1.5, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does minimatch contain malware?
No malware was identified in minimatch@3.1.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was minimatch checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan minimatch together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in minimatch@3.1.5, cost nothing.