# mz@2.7.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:19:26.000Z
- Files reviewed: 7
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/mz
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package mz@2.7.0 on Oct 6, 2026. An AI review of 7 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Sensitive module re-export

Finding ID: `NPS-AEE7A478E7C7`

File: `index.js:6`

The module re-exports Node.js built-in modules (fs, dns, zlib, crypto, readline, child_process) via relative paths (e.g., './fs', './dns'). While re-exporting built-ins is common in packages like 'browserify' shims, the child_process module can spawn shell commands and crypto can be abused for exfiltration. Without seeing the implementations of './fs', './dns', etc., it is not possible to confirm whether these are simple built-in passthroughs or malicious shims that intercept and exfiltrate data. The presence of child_process and crypto re-exports warrants caution.

### [medium] Potential code execution surface

Finding ID: `NPS-87BFFFE3C3DC`

File: `index.js:6`

Re-exporting child_process provides a direct path to process spawning and shell command execution. If the local './child_process' implementation wraps or modifies behavior (e.g., injecting commands, logging arguments, or proxying calls), this could enable command execution or credential theft. The same applies to crypto (key material) and fs (filesystem access). The relative paths make the actual implementation opaque from this file alone.

### [low] Import-time side effects

Finding ID: `NPS-C2DFE9327BDD`

File: `fs.js:1`

The module immediately requires 'any-promise', 'graceful-fs' (or 'fs'), and 'thenify-all', and calls thenify-all's withCallback on the fs object during import. While this is standard for a fs promise wrapper, it does execute code at import time and modifies the fs API surface, which could be unexpected in some contexts.

### [low] Potential dependency confusion / supply chain risk

Finding ID: `NPS-3F547F72601C`

File: `fs.js:2`

The module depends on 'any-promise', 'graceful-fs', and 'thenify-all'. If any of these dependencies were compromised, they could execute arbitrary code. However, this is a general supply chain risk, not a specific malicious pattern in this file.

## Files reviewed

- `fs.js` (medium): The code is a standard fs promise wrapper with no obvious malicious patterns, but it has import-time side effects and relies on external dependencies for core functionality.
- `index.js` (medium): The index file only re-exports six Node.js built-in modules via relative paths, but the child_process and crypto re-exports create a potential attack surface if the local implementations are malicious, so the package should be inspected further before trust.
- `child_process.js` (safe): No malicious patterns detected; the code simply promisifies Node.js child_process exec functions.
- `crypto.js` (safe): No malicious patterns detected; the code only promisifies standard crypto functions via thenify-all.
- `dns.js` (safe): No malicious patterns detected
- `readline.js` (safe): No malicious patterns detected; the code is a standard Promise-based wrapper for Node's readline module.
- `zlib.js` (safe): No malicious patterns detected; the file is a standard promisification wrapper for Node.js zlib module.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
