# minizlib@3.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:19:24.000Z
- Files reviewed: 4
- Findings: 2 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/minizlib@3.1.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package minizlib@3.1.0 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Private/internal Node.js API access

Finding ID: `NPS-3722B3F15416`

File: `dist/esm/index.js:128`

The code accesses private/internal properties of Node.js zlib handles (this.#handle._handle, _processChunk, _outBuffer, handle.params). These are undocumented internal APIs that can change between Node versions, and relying on them can cause crashes or unexpected behavior. It also temporarily overrides nativeHandle.close and this.#handle.close to no-ops, intercepting native handle lifecycle.

### [medium] Mutation of native object methods during execution

Finding ID: `NPS-8EC66A41F535`

File: `dist/esm/index.js:128`

The write() method temporarily replaces nativeHandle.close, this.#handle.close, and this.handle.flush with no-op or custom functions. While these are restored in finally blocks, if an unexpected error or re-entrant call occurs, global/native state could be left in a modified condition, potentially leading to resource leaks (native handles not closed) or altered behavior for other code using the same handles.

### [low] Monkey-patching of Node.js built-in Buffer.concat

Finding ID: `NPS-46C0735FE081`

File: `dist/commonjs/index.js:69`

The code temporarily overrides the global Buffer.concat method during write operations (via passthroughBufferConcat) and restores it afterwards. While intended as a performance optimization for the zlib wrapper, modifying a global built-in prototype/function is a risky pattern that can cause side effects or be exploited by other code observing or hooking these functions.

### [low] Access to internal Node.js zlib implementation details

Finding ID: `NPS-165222EDD83E`

File: `dist/commonjs/index.js:174`

The code reaches into private/internal properties of Node.js' zlib bindings (e.g., this.#handle._handle, nativeHandle.close, this.#handle._processChunk) and temporarily disables native handle closing. This implementation relies on undocumented internals that may behave differently across Node.js versions and is a maintenance/stability risk, though it does not appear malicious.

### [low] Monkey-patching global Buffer.concat

Finding ID: `NPS-4A74CB6C6792`

File: `dist/esm/index.js:8`

The code saves a reference to the global Buffer.concat, then reassigns Buffer.concat to a no-op function during _processChunk execution, and restores it afterward. This global mutation of a Node.js built-in could affect other code running concurrently in the same process, potentially breaking or altering behavior of unrelated modules. While the intent appears to be performance optimization (avoiding the Buffer.concat call inside zlib._processChunk), mutating a global built-in is a risky anti-pattern.

## Files reviewed

- `dist/commonjs/index.js` (medium): This appears to be a legitimate zlib/compression wrapper package (likely minizlib) that uses some risky monkey-patching and private Node.js internals, but no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
- `dist/esm/index.js` (medium): No malicious patterns (exfiltration, credential theft, shells, mining, or install-time payloads) were found, but the code performs risky global mutation of Buffer.concat and relies on/overrides private Node.js zlib internals, which is a security-relevant anti-pattern.
- `dist/commonjs/constants.js` (safe): Code only defines zlib constants and imports the standard zlib module, with no suspicious or malicious patterns detected.
- `dist/esm/constants.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of minizlib are flagged high or critical. The latest scanned version, 3.1.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.1.2 – 3.1.0 (`>=2.1.2 <=3.1.0`): medium (Global prototype/builtin monkey-patching +3 more)

## Scanned versions

- [3.1.0](https://security.togoder.click/npm/minizlib@3.1.0): medium, 2026-10-06T14:19:24.000Z
- [2.1.2](https://security.togoder.click/npm/minizlib@2.1.2): medium, 2026-10-04T16:55:53.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
