Summary
Togoder Security scanned the npm package minizlib@3.1.0 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Private/internal Node.js API access
NPS-3722B3F15416
The code accesses private/internal properties of Node.js zlib handles (this.#handle._handle, _processChunk, _outBuffer, handle.params). These are undocumented internal APIs that can change between Node versions, and relying on them can cause crashes or unexpected behavior. It also temporarily overrides nativeHandle.close and this.#handle.close to no-ops, intercepting native handle lifecycle.
Mutation of native object methods during execution
NPS-8EC66A41F535
The write() method temporarily replaces nativeHandle.close, this.#handle.close, and this.handle.flush with no-op or custom functions. While these are restored in finally blocks, if an unexpected error or re-entrant call occurs, global/native state could be left in a modified condition, potentially leading to resource leaks (native handles not closed) or altered behavior for other code using the same handles.
Monkey-patching of Node.js built-in Buffer.concat
NPS-46C0735FE081
The code temporarily overrides the global Buffer.concat method during write operations (via passthroughBufferConcat) and restores it afterwards. While intended as a performance optimization for the zlib wrapper, modifying a global built-in prototype/function is a risky pattern that can cause side effects or be exploited by other code observing or hooking these functions.
Access to internal Node.js zlib implementation details
NPS-165222EDD83E
The code reaches into private/internal properties of Node.js' zlib bindings (e.g., this.#handle._handle, nativeHandle.close, this.#handle._processChunk) and temporarily disables native handle closing. This implementation relies on undocumented internals that may behave differently across Node.js versions and is a maintenance/stability risk, though it does not appear malicious.
Monkey-patching global Buffer.concat
NPS-4A74CB6C6792
The code saves a reference to the global Buffer.concat, then reassigns Buffer.concat to a no-op function during _processChunk execution, and restores it afterward. This global mutation of a Node.js built-in could affect other code running concurrently in the same process, potentially breaking or altering behavior of unrelated modules. While the intent appears to be performance optimization (avoiding the Buffer.concat call inside zlib._processChunk), mutating a global built-in is a risky anti-pattern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/commonjs/index.js | medium | This appears to be a legitimate zlib/compression wrapper package (likely minizlib) that uses some risky monkey-patching and private Node.js internals, but no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were detected. |
| dist/esm/index.js | medium | No malicious patterns (exfiltration, credential theft, shells, mining, or install-time payloads) were found, but the code performs risky global mutation of Buffer.concat and relies on/overrides private Node.js zlib internals, which is a security-relevant anti-pattern. |
| dist/commonjs/constants.js | safe | Code only defines zlib constants and imports the standard zlib module, with no suspicious or malicious patterns detected. |
| dist/esm/constants.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of minizlib are flagged high or critical. The latest scanned version, 3.1.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.1.2 โ 3.1.0 | Needs review | 2 | >=2.1.2 <=3.1.0 | Global prototype/builtin monkey-patching; Native binding manipulation |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of minizlib
Frequently asked questions
Is minizlib safe to use?
No confirmed malware was found in minizlib@3.1.0, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does minizlib contain malware?
No malware was identified in minizlib@3.1.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was minizlib checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan minizlib together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in minizlib@3.1.0, cost nothing.