# minizlib@2.1.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:55:53.000Z
- Files reviewed: 2
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/minizlib@2.1.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package minizlib@2.1.2 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Native binding manipulation

Finding ID: `NPS-D1B2D30486CA`

File: `index.js:134`

The code directly accesses and mutates internal zlib handle properties (this[_handle]._handle, nativeHandle.close) to prevent native resource cleanup during _processChunk. This relies on undocumented Node.js internals and could lead to resource leaks, use-after-free conditions, or unexpected behavior if the internal implementation changes.

### [medium] Global prototype/builtin monkey-patching

Finding ID: `NPS-FBF3B40577D8`

File: `index.js:138`

The write() method temporarily reassigns the global Buffer.concat function to a custom implementation to intercept zlib's internal buffer concatenation. While it restores the original afterwards, mutating a global builtin is fragile and could interfere with other code running concurrently (e.g., in async callbacks or worker threads), potentially causing incorrect buffer behavior or unintended side effects.

### [low] Error listener manipulation

Finding ID: `NPS-2ED0C43B71F1`

File: `index.js:156`

The code calls removeAllListeners('error') on the underlying zlib handle after each processing chunk. This could inadvertently remove error listeners installed by other parts of the application or by Node.js core, potentially suppressing important error notifications.

## Files reviewed

- `index.js` (medium): No malicious patterns detected, but the code performs risky monkey-patching of global builtins and Node.js internals that could cause subtle side effects.
- `constants.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of minizlib are flagged high or critical. The latest scanned version, 3.1.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.1.2 – 3.1.0 (`>=2.1.2 <=3.1.0`): medium (Global prototype/builtin monkey-patching +3 more)

## Scanned versions

- [3.1.0](https://security.togoder.click/npm/minizlib@3.1.0): medium, 2026-10-06T14:19:24.000Z
- [2.1.2](https://security.togoder.click/npm/minizlib@2.1.2): medium, 2026-10-04T16:55:53.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
