Summary
Togoder Security scanned the npm package mz@2.7.0 on Oct 6, 2026. An AI review of 7 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Sensitive module re-export
NPS-AEE7A478E7C7
The module re-exports Node.js built-in modules (fs, dns, zlib, crypto, readline, child_process) via relative paths (e.g., './fs', './dns'). While re-exporting built-ins is common in packages like 'browserify' shims, the child_process module can spawn shell commands and crypto can be abused for exfiltration. Without seeing the implementations of './fs', './dns', etc., it is not possible to confirm whether these are simple built-in passthroughs or malicious shims that intercept and exfiltrate data. The presence of child_process and crypto re-exports warrants caution.
Potential code execution surface
NPS-87BFFFE3C3DC
Re-exporting child_process provides a direct path to process spawning and shell command execution. If the local './child_process' implementation wraps or modifies behavior (e.g., injecting commands, logging arguments, or proxying calls), this could enable command execution or credential theft. The same applies to crypto (key material) and fs (filesystem access). The relative paths make the actual implementation opaque from this file alone.
Import-time side effects
NPS-C2DFE9327BDD
The module immediately requires 'any-promise', 'graceful-fs' (or 'fs'), and 'thenify-all', and calls thenify-all's withCallback on the fs object during import. While this is standard for a fs promise wrapper, it does execute code at import time and modifies the fs API surface, which could be unexpected in some contexts.
Potential dependency confusion / supply chain risk
NPS-3F547F72601C
The module depends on 'any-promise', 'graceful-fs', and 'thenify-all'. If any of these dependencies were compromised, they could execute arbitrary code. However, this is a general supply chain risk, not a specific malicious pattern in this file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| fs.js | medium | The code is a standard fs promise wrapper with no obvious malicious patterns, but it has import-time side effects and relies on external dependencies for core functionality. |
| index.js | medium | The index file only re-exports six Node.js built-in modules via relative paths, but the child_process and crypto re-exports create a potential attack surface if the local implementations are malicious, so the package should be inspected further before trust. |
| child_process.js | safe | No malicious patterns detected; the code simply promisifies Node.js child_process exec functions. |
| crypto.js | safe | No malicious patterns detected; the code only promisifies standard crypto functions via thenify-all. |
| dns.js | safe | No malicious patterns detected |
| readline.js | safe | No malicious patterns detected; the code is a standard Promise-based wrapper for Node's readline module. |
| zlib.js | safe | No malicious patterns detected; the file is a standard promisification wrapper for Node.js zlib module. |
Frequently asked questions
Is mz safe to use?
No confirmed malware was found in mz@2.7.0, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does mz contain malware?
No malware was identified in mz@2.7.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was mz checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan mz together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in mz@2.7.0, cost nothing.