Togoder security

npm package security report

mz@2.7.0 security report

Risky patterns found that deserve a look.

Needs review Version 2.7.0 Files reviewed 7 Size 3.5 KB Scanned

Summary

Togoder Security scanned the npm package mz@2.7.0 on Oct 6, 2026. An AI review of 7 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
2
low

Findings 4

medium

Sensitive module re-export

NPS-AEE7A478E7C7

The module re-exports Node.js built-in modules (fs, dns, zlib, crypto, readline, child_process) via relative paths (e.g., './fs', './dns'). While re-exporting built-ins is common in packages like 'browserify' shims, the child_process module can spawn shell commands and crypto can be abused for exfiltration. Without seeing the implementations of './fs', './dns', etc., it is not possible to confirm whether these are simple built-in passthroughs or malicious shims that intercept and exfiltrate data. The presence of child_process and crypto re-exports warrants caution.

index.js:6
medium

Potential code execution surface

NPS-87BFFFE3C3DC

Re-exporting child_process provides a direct path to process spawning and shell command execution. If the local './child_process' implementation wraps or modifies behavior (e.g., injecting commands, logging arguments, or proxying calls), this could enable command execution or credential theft. The same applies to crypto (key material) and fs (filesystem access). The relative paths make the actual implementation opaque from this file alone.

index.js:6
low

Import-time side effects

NPS-C2DFE9327BDD

The module immediately requires 'any-promise', 'graceful-fs' (or 'fs'), and 'thenify-all', and calls thenify-all's withCallback on the fs object during import. While this is standard for a fs promise wrapper, it does execute code at import time and modifies the fs API surface, which could be unexpected in some contexts.

fs.js:1
low

Potential dependency confusion / supply chain risk

NPS-3F547F72601C

The module depends on 'any-promise', 'graceful-fs', and 'thenify-all'. If any of these dependencies were compromised, they could execute arbitrary code. However, this is a general supply chain risk, not a specific malicious pattern in this file.

fs.js:2

Files reviewed

FileVerdictWhat the reviewer saw
fs.js medium The code is a standard fs promise wrapper with no obvious malicious patterns, but it has import-time side effects and relies on external dependencies for core functionality.
index.js medium The index file only re-exports six Node.js built-in modules via relative paths, but the child_process and crypto re-exports create a potential attack surface if the local implementations are malicious, so the package should be inspected further before trust.
child_process.js safe No malicious patterns detected; the code simply promisifies Node.js child_process exec functions.
crypto.js safe No malicious patterns detected; the code only promisifies standard crypto functions via thenify-all.
dns.js safe No malicious patterns detected
readline.js safe No malicious patterns detected; the code is a standard Promise-based wrapper for Node's readline module.
zlib.js safe No malicious patterns detected; the file is a standard promisification wrapper for Node.js zlib module.

Frequently asked questions

Is mz safe to use?

No confirmed malware was found in mz@2.7.0, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does mz contain malware?

No malware was identified in mz@2.7.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was mz checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan mz together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in mz@2.7.0, cost nothing.

Related security reports