Summary
Togoder Security scanned the npm package minizlib@2.1.2 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Native binding manipulation
NPS-D1B2D30486CA
The code directly accesses and mutates internal zlib handle properties (this[_handle]._handle, nativeHandle.close) to prevent native resource cleanup during _processChunk. This relies on undocumented Node.js internals and could lead to resource leaks, use-after-free conditions, or unexpected behavior if the internal implementation changes.
Global prototype/builtin monkey-patching
NPS-FBF3B40577D8
The write() method temporarily reassigns the global Buffer.concat function to a custom implementation to intercept zlib's internal buffer concatenation. While it restores the original afterwards, mutating a global builtin is fragile and could interfere with other code running concurrently (e.g., in async callbacks or worker threads), potentially causing incorrect buffer behavior or unintended side effects.
Error listener manipulation
NPS-2ED0C43B71F1
The code calls removeAllListeners('error') on the underlying zlib handle after each processing chunk. This could inadvertently remove error listeners installed by other parts of the application or by Node.js core, potentially suppressing important error notifications.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | No malicious patterns detected, but the code performs risky monkey-patching of global builtins and Node.js internals that could cause subtle side effects. |
| constants.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of minizlib are flagged high or critical. The latest scanned version, 3.1.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.1.2 โ 3.1.0 | Needs review | 2 | >=2.1.2 <=3.1.0 | Global prototype/builtin monkey-patching; Native binding manipulation |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of minizlib
Frequently asked questions
Is minizlib safe to use?
No confirmed malware was found in minizlib@2.1.2, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does minizlib contain malware?
No malware was identified in minizlib@2.1.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was minizlib checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan minizlib together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in minizlib@2.1.2, cost nothing.