Togoder security

npm package security report

minizlib@3.1.0 security report

Risky patterns found that deserve a look.

Needs review Version 3.1.0 Files reviewed 4 Size 34.6 KB Scanned

Summary

Togoder Security scanned the npm package minizlib@3.1.0 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
3
low

Findings 5

medium

Private/internal Node.js API access

NPS-3722B3F15416

The code accesses private/internal properties of Node.js zlib handles (this.#handle._handle, _processChunk, _outBuffer, handle.params). These are undocumented internal APIs that can change between Node versions, and relying on them can cause crashes or unexpected behavior. It also temporarily overrides nativeHandle.close and this.#handle.close to no-ops, intercepting native handle lifecycle.

dist/esm/index.js:128
medium

Mutation of native object methods during execution

NPS-8EC66A41F535

The write() method temporarily replaces nativeHandle.close, this.#handle.close, and this.handle.flush with no-op or custom functions. While these are restored in finally blocks, if an unexpected error or re-entrant call occurs, global/native state could be left in a modified condition, potentially leading to resource leaks (native handles not closed) or altered behavior for other code using the same handles.

dist/esm/index.js:128
low

Monkey-patching of Node.js built-in Buffer.concat

NPS-46C0735FE081

The code temporarily overrides the global Buffer.concat method during write operations (via passthroughBufferConcat) and restores it afterwards. While intended as a performance optimization for the zlib wrapper, modifying a global built-in prototype/function is a risky pattern that can cause side effects or be exploited by other code observing or hooking these functions.

dist/commonjs/index.js:69
low

Access to internal Node.js zlib implementation details

NPS-165222EDD83E

The code reaches into private/internal properties of Node.js' zlib bindings (e.g., this.#handle._handle, nativeHandle.close, this.#handle._processChunk) and temporarily disables native handle closing. This implementation relies on undocumented internals that may behave differently across Node.js versions and is a maintenance/stability risk, though it does not appear malicious.

dist/commonjs/index.js:174
low

Monkey-patching global Buffer.concat

NPS-4A74CB6C6792

The code saves a reference to the global Buffer.concat, then reassigns Buffer.concat to a no-op function during _processChunk execution, and restores it afterward. This global mutation of a Node.js built-in could affect other code running concurrently in the same process, potentially breaking or altering behavior of unrelated modules. While the intent appears to be performance optimization (avoiding the Buffer.concat call inside zlib._processChunk), mutating a global built-in is a risky anti-pattern.

dist/esm/index.js:8

Files reviewed

FileVerdictWhat the reviewer saw
dist/commonjs/index.js medium This appears to be a legitimate zlib/compression wrapper package (likely minizlib) that uses some risky monkey-patching and private Node.js internals, but no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
dist/esm/index.js medium No malicious patterns (exfiltration, credential theft, shells, mining, or install-time payloads) were found, but the code performs risky global mutation of Buffer.concat and relies on/overrides private Node.js zlib internals, which is a security-relevant anti-pattern.
dist/commonjs/constants.js safe Code only defines zlib constants and imports the standard zlib module, with no suspicious or malicious patterns detected.
dist/esm/constants.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of minizlib are flagged high or critical. The latest scanned version, 3.1.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.1.23.1.0
VersionsVerdictCountRangeTop findings
2.1.2 โ€“ 3.1.0 Needs review 2 >=2.1.2 <=3.1.0 Global prototype/builtin monkey-patching; Native binding manipulation

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of minizlib

VersionVerdictFilesScanned
3.1.0 Needs review 4 Oct 6, 2026
2.1.2 Needs review 2 Oct 4, 2026

Frequently asked questions

Is minizlib safe to use?

No confirmed malware was found in minizlib@3.1.0, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does minizlib contain malware?

No malware was identified in minizlib@3.1.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was minizlib checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan minizlib together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in minizlib@3.1.0, cost nothing.

Related security reports