Togoder security

npm package security report

minizlib@2.1.2 security report

Risky patterns found that deserve a look.

Needs review Version 2.1.2 Files reviewed 2 Size 12.9 KB Scanned

Summary

Togoder Security scanned the npm package minizlib@2.1.2 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Native binding manipulation

NPS-D1B2D30486CA

The code directly accesses and mutates internal zlib handle properties (this[_handle]._handle, nativeHandle.close) to prevent native resource cleanup during _processChunk. This relies on undocumented Node.js internals and could lead to resource leaks, use-after-free conditions, or unexpected behavior if the internal implementation changes.

index.js:134
medium

Global prototype/builtin monkey-patching

NPS-FBF3B40577D8

The write() method temporarily reassigns the global Buffer.concat function to a custom implementation to intercept zlib's internal buffer concatenation. While it restores the original afterwards, mutating a global builtin is fragile and could interfere with other code running concurrently (e.g., in async callbacks or worker threads), potentially causing incorrect buffer behavior or unintended side effects.

index.js:138
low

Error listener manipulation

NPS-2ED0C43B71F1

The code calls removeAllListeners('error') on the underlying zlib handle after each processing chunk. This could inadvertently remove error listeners installed by other parts of the application or by Node.js core, potentially suppressing important error notifications.

index.js:156

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium No malicious patterns detected, but the code performs risky monkey-patching of global builtins and Node.js internals that could cause subtle side effects.
constants.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of minizlib are flagged high or critical. The latest scanned version, 3.1.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.1.23.1.0
VersionsVerdictCountRangeTop findings
2.1.2 โ€“ 3.1.0 Needs review 2 >=2.1.2 <=3.1.0 Global prototype/builtin monkey-patching; Native binding manipulation

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of minizlib

VersionVerdictFilesScanned
3.1.0 Needs review 4 Oct 6, 2026
2.1.2 Needs review 2 Oct 4, 2026

Frequently asked questions

Is minizlib safe to use?

No confirmed malware was found in minizlib@2.1.2, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does minizlib contain malware?

No malware was identified in minizlib@2.1.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was minizlib checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan minizlib together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in minizlib@2.1.2, cost nothing.

Related security reports