Summary
Togoder Security scanned the npm package next-auth@4.24.15 on Oct 6, 2026. An AI review of 226 source files produced 2 high, 23 medium, 40 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 65
Prototype Pollution
NPS-9485C7D025E5
The recursive merge function does not validate or skip dangerous keys like '__proto__', 'constructor', or 'prototype'. An attacker controlling the source object can inject properties into Object.prototype, potentially leading to RCE or DoS in applications using this utility. This is a well-known vulnerability class in merge implementations (e.g., CVE-2020-7598 for minimist, CVE-2018-3721 for lodash.merge).
Unsafe Object Assignment
NPS-D789284BFD18
Object.assign(target, { [key]: source[key] }) is called on user-controlled keys without filtering. When key is '__proto__', this can mutate the prototype chain of target and potentially global Object.prototype, enabling prototype pollution attacks.
Potential open redirect / SSRF via callback redirect
NPS-6AB3016B015C
The function accepts user-controlled paramValue or cookieValue and passes it to callbacks.redirect(). If the redirect callback is not implemented with a strict allowlist, an attacker could supply an arbitrary external URL, causing an open redirect or SSRF. The baseUrl is provided, but enforcement depends entirely on the callback implementation which is outside this file.
Missing URL validation before use
NPS-EE14914721FE
There is no validation that the resolved callbackUrl stays within the expected origin or against a set of trusted callback URLs. The result is returned directly and may be used in redirects or cookie setting, which can enable phishing or credential leakage if misused.
weak hash-based CSRF token validation
NPS-331D7E8381E1
The CSRF token is compared to the body value using the === operator, which is not constant-time and may be vulnerable to timing attacks. Additionally, the hash comparison uses === which is also not constant-time. While not a backdoor, this is a security weakness in an authentication-related module.
Unsafe HTML injection
NPS-CEF3959113D5
The code uses dangerouslySetInnerHTML with a template literal that interpolates theme.brandColor directly into a <style> block. If theme.brandColor is attacker-controlled (e.g., from query parameters or config), it could lead to CSS injection or, with crafted payloads, script execution in some contexts. The value is not sanitized or validated.
Cross-Site Scripting (XSS) via dangerouslySetInnerHTML
NPS-E67DC6880BE3
The component injects theme.brandColor and theme.buttonText directly into <style> tags using dangerouslySetInnerHTML without sanitization. If theme values are attacker-controlled, this could lead to script injection or CSS-based data exfiltration.
Form action to external URL
NPS-AD7211D0B322
OAuth and email forms submit credentials/CSRF tokens to provider.signinUrl and provider.callbackUrl without visible validation. If these props are derived from untrusted input, credentials could be exfiltrated to an attacker-controlled endpoint.
Potential Open Redirect / Phishing via callbackUrl
NPS-DEF16A12B9EB
The callbackUrl prop is placed into a hidden form input and sent to the authentication provider without validation. A crafted callbackUrl could redirect users to a malicious site after sign-in.
XSS via dangerouslySetInnerHTML
NPS-E778F8565401
The component injects theme.brandColor and theme.buttonText directly into a <style> tag using dangerouslySetInnerHTML without sanitization. If these theme values are attacker-controlled, this allows arbitrary CSS injection, which can lead to data exfiltration via CSS selectors, UI redressing, or other client-side attacks. A malicious value such as '}' followed by CSS rules could break out of the intended custom property scope.
Cross-Site Scripting (XSS) via dangerouslySetInnerHTML
NPS-FCFE9DA459F8
The theme.brandColor value is interpolated directly into an inline <style> tag using dangerouslySetInnerHTML without sanitization. If an attacker can control the theme configuration (e.g., via a crafted callback URL, environment configuration, or user-supplied theme), they can inject arbitrary CSS or break out of the style block to inject HTML/JS, leading to a stored/reflected XSS vulnerability.
Missing issuer validation
NPS-36A700DCBE17
No validation or sanitization of options.issuer is performed (e.g., ensuring it is a trusted domain or HTTPS endpoint). This weakens protection against SSRF-style or open-redirect-style abuse if the provider is configured with attacker-controlled values.
Dynamic URL construction from user input
NPS-0F0F42362569
The provider constructs authorization, token, and userinfo URLs by directly interpolating options.issuer into template strings. If options.issuer is influenced by untrusted input, this could lead to token/data exfiltration to an attacker-controlled server.
account linking logic
NPS-0571FAC7E8D3
The code includes a dangerous account linking feature gated behind 'allowDangerousEmailAccountLinking'. When enabled, an OAuth provider's email is trusted to automatically link to an existing account, potentially allowing account takeover if the provider does not verify emails. This is a known security risk but is an intentional feature with explicit opt-in and documented warning in comments.
Weak cryptographic secret generation
NPS-0F8848ACEB57
createSecret falls back to deriving a secret by hashing JSON.stringify({ ...url, ...authOptions }) when authOptions.secret is missing. This fallback secret is deterministic, derived from potentially low-entropy or predictable configuration data, and is not cryptographically random. The code comment even acknowledges this is a temporary fallback. A weak, predictable secret undermines CSRF protection, cookie signing, and token hashing, potentially allowing attackers to forge tokens or cookies.
XSS via dangerouslySetInnerHTML
NPS-D8E2B6CB4933
The component injects theme.brandColor directly into a <style> tag using dangerouslySetInnerHTML without sanitization. If an attacker can control the theme object (e.g., via configuration or URL parameters), they could inject arbitrary CSS or break out of the style context, potentially leading to CSS injection or XSS depending on the rendering context.
Potential XSS via dangerouslySetInnerHTML
NPS-F18FEF201780
The component injects theme.brandColor and theme.buttonText directly into a <style> tag using dangerouslySetInnerHTML without sanitization. If an attacker can control these theme values (e.g., via configuration or user input), they could inject malicious CSS or break out of the style context to execute JavaScript.
Potential XSS via unsanitized provider logo URL
NPS-70F0884DF725
The 'logo' and 'logoDark' values from provider.style are used directly in img src attributes after a simple prefix check. If these values can be controlled by an attacker (e.g., via a malicious provider configuration), they could inject javascript: URLs or other malicious content.
XSS via dangerouslySetInnerHTML with interpolated theme values
NPS-AE064898038A
theme.brandColor and theme.buttonText are injected directly into a <style> tag using dangerouslySetInnerHTML without sanitization. If these theme values are attacker-controlled or come from untrusted configuration, this enables CSS injection or potentially XSS (e.g., via </style><script>...</script>). This is a common security concern in authentication UI packages where theme configuration may be user-supplied.
XSS via dangerouslySetInnerHTML
NPS-2CDEFB27E74F
The theme.brandColor value is interpolated directly into a <style> tag using dangerouslySetInnerHTML without sanitization. If an attacker can control or influence the theme.brandColor value (e.g. through configuration or URL parameters persisted in a session), they could inject arbitrary CSS or potentially break out of the style context to inject HTML/script content, leading to cross-site scripting.
File system access outside package scope
NPS-96C6659A100D
In production mode, the code reads '/src/css/index.css' via an absolute path from the filesystem root. This path is outside the package directory and could be used to read arbitrary files if the path were controllable, though here it is hardcoded. In development mode it reads from node_modules/next-auth/css/index.css, which is within the project but still reads a file outside the package's own scope.
Insecure OAuth configuration
NPS-B5080D509DCD
The 'checks' property is set to ['none'], disabling OAuth state parameter validation. This disables CSRF protection in the OAuth flow, which could allow attackers to perform login CSRF attacks.
Global logger override
NPS-693EA3F09CAF
setLogger allows overriding the global _logger.error/warn/debug methods. If a malicious dependency calls setLogger with an attacker-controlled logger, it could intercept and exfiltrate all subsequent application errors and warnings, which may contain secrets. However, this is the documented API of the package.
Data exfiltration
NPS-754D43BD5702
The proxyLogger function sends log data (including error metadata, which may contain sensitive information like tokens, session data, or stack traces) to a server-side endpoint /_log. While this is presented as a logging proxy for NextAuth.js, it could be abused to exfiltrate sensitive runtime data if the endpoint is attacker-controlled or if the metadata contains secrets. The use of navigator.sendBeacon and fetch with keepalive indicates intent to transmit data reliably, even on page unload.
Suspicious network requests
NPS-7B0115C1F9E8
The proxyLogger dynamically constructs a URL using a basePath argument and sends POST requests with log data. If the basePath is not strictly validated, it could be manipulated to send data to an arbitrary external server. Additionally, the code runs in the browser and could be triggered by any logger level (error, warn, debug), potentially leaking user information.
predictable token derivation via secret concatenation
NPS-81373F3D8B2A
The CSRF token hash is computed by concatenating the token and options.secret directly without a delimiter. If the secret can be controlled or guessed, this could allow token forgery. However, the token is 32 random bytes, making brute force infeasible.
URL injection / open redirect potential
NPS-9E6142CA9DF5
The signinPageUrl is constructed by concatenating url with '/signin'. If url is not properly validated, this could allow open redirect or link manipulation. However, url is expected to be a URL object from the framework, reducing risk.
Potential CSS Injection
NPS-4D7F7D3A7F94
User-controlled values (theme.brandColor, theme.buttonText) are set via document.documentElement.style.setProperty and injected into style tags. This may allow CSS injection attacks such as UI redressing or style-based exfiltration.
Potential open redirect / untrusted URL rendering
NPS-01321D4D92D5
The component renders url.origin and url.host directly into an anchor href. If the url prop is derived from untrusted input (e.g., request query parameters), this can be abused for phishing or open redirect attacks, though Preact escaping limits direct XSS here.
Top-level code execution on import
NPS-9C23BF972DFB
The function FACEIT is exported and called when the provider is instantiated. The Authorization header is built using Buffer.from with options.clientId and options.clientSecret at the time the function is invoked. This is normal for OAuth configuration and does not execute at module import time by itself.
Credential handling in headers
NPS-AE80A8E158D8
The code constructs a Basic Authorization header by base64-encoding the clientId and clientSecret. While this is standard OAuth practice, the credentials are embedded directly into a header object at provider initialization. This is expected behavior for OAuth providers, but it means the client secret is present in memory and potentially in logs if headers are logged.
credential in URL
NPS-BBBE64C61FF0
The OAuth access token is appended as a query parameter (oauth_token) to the Foursquare API URL. Query parameters may be logged by servers, proxies, or CDNs, exposing the token. This is a security best practice violation, though it matches Foursquare's documented OAuth 2.0 flow.
unhandled request errors
NPS-BC36CD21CB59
The HTTP request only races 'response' and 'timeout' events. Network errors (e.g., DNS failure, connection refused) emit an 'error' event that is not handled, which can cause an unhandled 'error' event and crash the process.
Elevated OAuth scope request
NPS-683B0F1D2FA3
The authorization endpoint requests the 'identity' scope (typically mapped to account identity access). While 'identity' is a common scope for user profile retrieval, the static embedding of scope in the authorization URL is standard for this provider type. No exfiltration, credential harvesting, or suspicious behavior is present. Noted as a minor observation for transparency only.
Malformed URL configuration
NPS-435F1970DDF7
The token endpoint URL contains a leading space (' https://www.reddit.com/api/v1/access_token'), which is likely a copy-paste error. While not inherently malicious, it could cause runtime failures or unexpected behavior in URL parsing, and may indicate insufficient code review. Legitimate OAuth provider definitions should use a clean, properly formatted URL.
Standard Network Request
NPS-19196CB03FC9
The code performs an HTTPS request to the official Trakt API endpoint (api.trakt.tv) for user info, using OAuth tokens and API key passed in headers. This is expected OAuth behavior and not data exfiltration.
Credential Handling
NPS-E24896178CA3
Uses context.tokens.access_token and context.provider.clientId for authentication with the Trakt API. These are standard OAuth credentials, not harvested from sensitive files or environment variables.
Environment variable harvesting
NPS-8770C60C6959
The code reads process.env.NEXTAUTH_URL, process.env.VERCEL_URL, and process.env.NEXTAUTH_URL_INTERNAL to construct authentication URLs. While these are standard NextAuth configuration variables, accessing environment variables at module load time could expose sensitive configuration if these values are inadvertently logged or transmitted.
BroadcastChannel usage for cross-tab communication
NPS-D1BA5006C73F
The code uses BroadcastChannel to synchronize session state across browser tabs. While not inherently malicious, it can be used to propagate session data between tabs, which might be concerning if origin checks are not properly enforced.
Dynamic redirect to user-controlled URLs
NPS-017DDB6398A7
In signIn and signOut functions, window.location.href is set to a URL derived from server response (data.url) or callbackUrl parameter. If an attacker can influence callbackUrl or the server response, this could lead to open redirect vulnerabilities. However, this is expected behavior for authentication libraries.
Limited network request with cookie forwarding
NPS-90CE3CB11DE5
fetchData constructs a URL from a caller-supplied base URL and forwards the incoming request's cookie header to it. This is standard behavior for NextAuth clients to propagate session cookies to its own backend, but if baseUrl/baseUrlServer is attacker-influenced, cookies could be sent to an unintended host. In normal usage these values come from trusted configuration, so this is informational rather than malicious.
Unvalidated JSON parsing from storage events
NPS-B22552DC63F9
BroadcastChannel.receive parses event.newValue JSON without deep validation. A malformed or malicious localStorage entry for the channel name could cause JSON.parse to throw inside the storage event handler; the try/catch absence there is a robustness concern, not a code-execution or exfiltration issue.
Dynamic property access from request body
NPS-1D4DCFC6E3FE
In the '_log' POST action, the logger level is taken from req.body.level and used as a property lookup on the logger object: logger[level](code, metadata). While the logger object itself is controlled by the library author and set via setLogger, an attacker could pass arbitrary level values from the request. In the typical pino-based logger implementation this would just fail or no-op for invalid levels, but if a custom logger with unexpected properties/methods were used, this could invoke unintended functions. This is a minor robustness concern rather than a clear malicious pattern.
Origin detection via x-forwarded-host
NPS-718160DE2BEB
detectOrigin uses client-supplied x-forwarded-host and x-forwarded-proto headers to compute the origin used for redirects and callback URL construction. If a deployment trusts these headers from untrusted clients, it can enable host-header injection / open redirect issues. This is standard NextAuth behavior and a known configuration concern, not a malicious pattern.
input validation
NPS-82C311F6CC2C
The function validates that account.providerAccountId and account.type exist and that account.type is either 'email' or 'oauth'. This is good practice and limits unexpected inputs.
token_in_url
NPS-D63CE70127B3
The unhashed verification token is included in the email callback URL, which could leak via logs, referrers, or browser history. This is a standard part of the email sign-in flow (the token is hashed before DB storage), but proper handling (short expiry, single use, HTTPS) is required.
token_logging_risk
NPS-DB7AD2D87534
No explicit redaction or sanitization of token before embedding in URL/query string; if the URL is logged or captured by analytics, the token could be exposed.
Top-level state mutation
NPS-7D81DCBD824E
The module exports a module-level mutable Map (oAuth1TokenStore). This is not malicious but could be a source of cross-request state leakage or memory growth if not managed carefully by callers.
Global State Modification
NPS-E664F535BCE5
custom.setHttpOptionsDefaults(provider.httpOptions) mutates global state of the openid-client library, which could affect other clients using the same library instance. This is a design concern rather than a malicious pattern.
Dynamic URL Configuration
NPS-5F56953668C5
The code uses provider.wellKnown for issuer discovery via Issuer.discover(), and constructs Issuer with endpoints from options.provider. If these values are attacker-controlled, they could redirect OAuth flows to malicious servers. However, this is expected OAuth client configuration behavior and the values come from internal options, not external input.
No external data exfiltration or malicious patterns
NPS-7C940252AD92
The file only uses Node.js crypto.createHash for hashing and does not perform any network requests, file system access outside package scope, process spawning, dynamic code execution, environment variable harvesting, or obfuscated behavior. The code appears to be part of an authentication library (likely NextAuth.js) and is functionally benign.
Secret material concatenation in hash input
NPS-30DC23F3623F
hashToken concatenates the token directly with the provider secret (or default secret) before SHA-256 hashing without any delimiter or HMAC construction. While not directly malicious, this pattern can be vulnerable to length-extension or ambiguity issues depending on usage. More importantly, it demonstrates that secrets are embedded in hash inputs, which could be exposed if the code is misused or if hash outputs are logged.
Potential open redirect / untrusted URL usage
NPS-7F4521864289
The signinPageUrl is constructed by concatenating url (an InternalUrl type) with '/signin' and used as the href of anchor tags. If url is derived from untrusted input, this could enable open redirect or phishing attacks.
Untrusted image source
NPS-D42A7AF48DFE
theme.logo is used directly as the src attribute of an <img> tag without validation. A malicious theme could cause the browser to load an external image, potentially leaking referrer information or enabling tracking.
Potential open redirect / CSRF token leakage
NPS-83736560114A
The callbackUrl parameter is passed directly into a hidden form field without validation. While this is typical for OAuth flows, if the callbackUrl is not validated server-side, it could lead to open redirect vulnerabilities. Similarly, csrfToken is exposed in the form, but this is expected behavior for CSRF protection.
Unvalidated image source
NPS-B3AA75D031FB
theme.logo is used directly as an <img> src attribute without validation. A malicious or external URL could be used for tracking, data exfiltration via referrer headers, or UI redressing. Low severity as it is a standard pattern for theme customization.
Potential open redirect / unvalidated URL
NPS-AB220836B8C2
The url.origin value is used directly as an href attribute. If the InternalUrl object is derived from user-supplied or request-controlled input without validation, this could lead to an open redirect or phishing link. However, based on the interface name (InternalUrl) and typical usage in NextAuth-style code, this is likely trusted internal data.
Top-level code execution
NPS-DC6900D478DD
The path is computed at module load time (top-level), meaning the path resolution and potential file read behavior is determined at import time. This is not malicious per se, but it is a pattern that executes at import.
Environment variable usage
NPS-C2C98DB21C6F
The code uses process.env.NODE_ENV to determine which file path to read. This is a standard pattern and not inherently malicious, but it does rely on environment variables for control flow.
Legitimate network request
NPS-B2E6674B7B34
The code makes standard GitHub OAuth API calls to fetch user profile and email data, which is expected for an OAuth provider implementation.
Access Token in URL
NPS-7D49239413B7
The access token is placed in the URL path when fetching the user profile, which is a common OAuth pattern for this provider but could expose the token in logs or referrer headers. This is not malicious.
Suspicious URL formatting
NPS-3F7B2EF88CF5
The token endpoint URL contains a leading space (' https://www.reddit.com/api/v1/access_token'). In OAuth flows, a malformed URL like this could cause errors or potentially be exploited if not trimmed, though it is more likely a typo. It is unusual and could indicate tampering or a mistake.
Overly permissive profile mapping
NPS-CC35DC3AB6F7
The profile function returns null for name and email and uses profile.user_id as id without validation. While not directly malicious, returning null for required fields could lead to unexpected behavior in downstream applications.
Error object mutation
NPS-075F55D5B2BF
formatError mutates the input error object by assigning o.error and o.message. This side-effect could cause unexpected behavior in the caller's error object, including leaking sensitive properties that are later serialized.
Data exfiltration to internal endpoint
NPS-CCAF2E250AFA
proxyLogger sends client-side log messages (including error metadata) to a server endpoint /_log via sendBeacon or fetch. While this is intended for error reporting to the application's own backend (basePath), it still constitutes data leaving the client and could leak sensitive information present in error metadata if not properly sanitized. The endpoint is constructed from a user-supplied basePath, which could be tampered with to redirect logs to an attacker-controlled server.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| core/lib/callback-url.js | medium | No overtly malicious code (no exfiltration, obfuscation, or process spawning), but the callback URL resolution relies on an external redirect callback and lacks origin validation, creating a potential open redirect/SSRF risk depending on caller implementation. |
| core/lib/csrf-token.js | medium | No malicious behavior detected, but the CSRF token validation uses non-constant-time comparisons which could leak information through timing side-channels. |
| core/pages/error.js | medium | The error page component contains a potential unsafe HTML injection via dangerouslySetInnerHTML with unsanitized theme.brandColor, but no other malicious patterns such as exfiltration, credential harvesting, or dynamic code execution were found. |
| core/pages/signin.js | medium | No overtly malicious code was found, but the component contains multiple injection and redirect risks (unsanitized dangerouslySetInnerHTML, unvalidated callbackUrl, and external form actions) that could be exploited if props are attacker-controlled. |
| core/pages/signout.js | medium | No malicious intent detected, but the code uses dangerouslySetInnerHTML with unsanitized theme values, creating a potential CSS injection/XSS vector. |
| core/pages/verify-request.js | medium | This is a legitimate NextAuth.js verification page component, but it introduces a potential XSS vector through unsanitized interpolation of theme.brandColor into inline styles via dangerouslySetInnerHTML. |
| providers/boxyhq-saml.js | medium | No overt malicious patterns (no exfiltration, obfuscation, process spawning, or credential harvesting) were found, but the provider builds OAuth endpoint URLs from an unvalidated options.issuer, which is a security hardening concern. |
| providers/faceit.js | medium | The code is a standard OAuth provider configuration for FACEIT with no malicious patterns, but it handles client credentials in constructed headers as expected for OAuth flows. |
| providers/foursquare.js | medium | The Foursquare OAuth provider code appears legitimate with no malicious patterns; minor security hygiene issues include passing the access token as a URL query parameter and incomplete error handling on the HTTPS request. |
| providers/reddit.js | medium | No malicious patterns detected; only a minor formatting issue in the token URL and a standard OAuth scope declaration are present. |
| react/index.js | medium | The code appears to be the legitimate next-auth React client library; no malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected, though standard environment variable access and dynamic redirects are present as expected for authentication functionality. |
| src/core/lib/utils.ts | medium | The code is not malicious but contains a weak fallback secret generation pattern that could reduce security if used without an explicit secret in production. |
| src/core/pages/error.tsx | medium | The code contains minor security concerns (unsanitized CSS injection and untrusted URL/image usage) but no clear malicious patterns such as data exfiltration, credential harvesting, or backdoor installation. |
| src/core/pages/signin.tsx | medium | The code contains potential XSS vectors through unsanitized theme values and logo URLs, but no clear malicious intent such as data exfiltration, backdoors, or code execution. |
| src/core/pages/signout.tsx | medium | No malicious code detected, but the component unsafely interpolates theme values into dangerouslySetInnerHTML, posing a potential XSS/CSS injection risk if theme inputs are not trusted. |
| src/core/pages/verify-request.tsx | medium | The component contains a potential XSS vector through unsanitized CSS injection via dangerouslySetInnerHTML using the theme.brandColor prop, though no clear malicious patterns like exfiltration or backdoors are present. |
| src/css/index.ts | medium | The code reads a CSS file from the filesystem, using an absolute path in production that could potentially access files outside the package scope, but no clear malicious intent or data exfiltration is present. |
| src/providers/reddit.js | medium | The code appears to be a standard OAuth provider configuration for Reddit, but contains a suspicious leading space in the token URL, which is likely a typo but warrants caution. |
| src/providers/salesforce.ts | medium | The code appears to be a legitimate Salesforce OAuth provider but disables critical OAuth security checks (state parameter validation) which could introduce CSRF vulnerabilities. |
| src/utils/logger.ts | medium | The code is a legitimate logging utility (appears to be NextAuth.js) with expected logging and client-to-server error proxying behavior; no clear malicious intent, but it does send client-side error metadata to a server endpoint and allows global logger overrides, which carry low-to-medium data exposure risks. |
| utils/logger.js | medium | The logger utility contains a client-side logging proxy that transmits log data to a server endpoint, which could lead to data exfiltration if the endpoint is misconfigured or controlled by an attacker. |
| utils/merge.js | medium | The merge utility contains a prototype pollution vulnerability due to missing validation of dangerous property keys like __proto__ and constructor, which could enable privilege escalation or RCE in downstream consumers. |
| client/_utils.js | safe | No malicious patterns detected; the code contains standard NextAuth utility functions for API fetching and cross-tab communication without data exfiltration, obfuscation, or privilege escalation. |
| core/errors.js | safe | No malicious patterns detected in the analyzed error handling module. |
| core/index.js | safe | No malicious patterns detected; the code appears to be a standard authentication handler from NextAuth.js with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity. |
Show 201 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| core/init.js | safe | This is standard NextAuth.js authentication initialization code with no malicious patterns detected. |
| core/lib/assert.js | safe | No malicious patterns detected |
| core/lib/callback-handler.js | safe | No malicious patterns detected; the code implements standard authentication callback handling without exfiltration, obfuscation, or suspicious behavior. |
| core/lib/cookie.js | safe | No malicious patterns detected |
| core/lib/default-callbacks.js | safe | No malicious patterns detected |
| core/lib/email/getUserFromEmail.js | safe | No malicious patterns detected; the function simply retrieves a user by email via an adapter and returns a default object if not found. |
| core/lib/email/signin.js | safe | No malicious patterns detected; the code performs standard email verification token generation and delivery using secure random bytes. |
| core/lib/oauth/authorization-url.js | safe | No malicious patterns detected; the code implements standard OAuth 1.0 and OpenID authorization URL generation without any exfiltration, credential harvesting, obfuscation, or process execution. |
| core/lib/oauth/callback.js | safe | No malicious patterns detected; the code is a standard OAuth callback handler for NextAuth.js that uses the openid-client library and performs expected OAuth flow operations. |
| core/lib/oauth/checks.js | safe | The code implements standard OpenID Connect OAuth checks (PKCE, state, nonce) with encrypted JWT cookies and contains no malicious patterns, exfiltration, or dangerous dynamic execution. |
| core/lib/oauth/client-legacy.js | safe | No malicious patterns detected; the code only wraps OAuth1 library methods with promisified versions and defines an in-memory token store. |
| core/lib/oauth/client.js | safe | No malicious patterns detected; the code is a standard OpenID client setup using the openid-client library. |
| core/lib/providers.js | safe | No malicious patterns detected; the code performs OAuth provider configuration normalization without exfiltration, credential harvesting, or dynamic code execution. |
| core/lib/utils.js | safe | No malicious patterns detected; the code uses standard cryptographic hashing for token and secret generation without exfiltration, obfuscation, or process execution. |
| core/pages/index.js | safe | No malicious patterns detected; the file is a standard NextAuth server-side rendering utility. |
| core/routes/callback.js | safe | No malicious patterns detected; the file contains standard OAuth/email/credentials callback logic with no data exfiltration, credential harvesting, dynamic code execution, or suspicious process/network activity. |
| core/routes/index.js | safe | No malicious patterns detected |
| core/routes/providers.js | safe | No malicious patterns detected; the code is a simple pure function that transforms provider metadata into a JSON response body. |
| core/routes/session.js | safe | No malicious patterns detected; the code is a standard NextAuth.js session handler with no data exfiltration, credential harvesting, obfuscation, or suspicious system interactions. |
| core/routes/signin.js | safe | No malicious patterns detected; the code is a standard NextAuth.js sign-in route handling OAuth and email authentication flows. |
| core/routes/signout.js | safe | No malicious patterns detected; the code appears to be a legitimate sign-out handler for an authentication library with no data exfiltration, obfuscation, or system manipulation. |
| core/types.js | safe | No malicious patterns detected |
| css/index.js | safe | No malicious patterns detected |
| index.js | safe | No malicious patterns detected |
| jwt/index.js | safe | The code implements standard JWT encoding/decoding using the jose library with proper key derivation and no malicious patterns detected. |
| jwt/types.js | safe | No malicious patterns detected |
| middleware.js | safe | This is a standard Babel-compiled CommonJS module re-exporting middleware from ./next/middleware, with no malicious patterns detected. |
| next/index.js | safe | This is legitimate NextAuth.js integration code with no malicious patterns detected. |
| next/middleware.js | safe | This is a legitimate NextAuth.js middleware file implementing authentication/authorization checks with no malicious patterns detected. |
| next/utils.js | safe | No malicious patterns detected; the code contains only standard HTTP utility functions for cookie handling, body parsing, and response construction. |
| providers/42-school.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for 42 School with no dynamic code execution, data exfiltration, or credential harvesting. |
| providers/apple.js | safe | No malicious patterns detected; this is a standard NextAuth.js Apple OAuth provider configuration file. |
| providers/atlassian.js | safe | No malicious patterns detected |
| providers/auth0.js | safe | No malicious patterns detected |
| providers/authentik.js | safe | No malicious patterns detected |
| providers/azure-ad-b2c.js | safe | No malicious patterns detected; the code is a straightforward Azure AD B2C OAuth provider configuration without any data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| providers/azure-ad.js | safe | No malicious patterns detected; this is a standard Azure AD OAuth provider implementation for NextAuth.js with expected network calls to Microsoft Graph for user profile photos. |
| providers/battlenet.js | safe | This is a benign NextAuth.js Battle.net OAuth provider definition with no malicious patterns, network exfiltration, credential harvesting, dynamic code execution, or install-time behavior. |
| providers/box.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for Box with no network, filesystem, or code execution behavior. |
| providers/bungie.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Bungie. |
| providers/cognito.js | safe | The Cognito OAuth provider is a standard, benign authentication configuration module with no malicious patterns, no dynamic execution, no network calls, no file system or process manipulation, and no credential harvesting. |
| providers/coinbase.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for Coinbase with only static URLs and no suspicious operations. |
| providers/credentials.js | safe | No malicious patterns detected |
| providers/discord.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for Discord with no data exfiltration, credential harvesting, obfuscation, or network activity beyond documented OAuth endpoints. |
| providers/dropbox.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Dropbox. |
| providers/duende-identity-server6.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Duende IdentityServer6 with no exfiltration, obfuscation, or execution of untrusted code. |
| providers/email.js | safe | No malicious patterns detected; the code is a standard NextAuth email provider using nodemailer to send verification emails. |
| providers/eveonline.js | safe | The code defines a standard OAuth provider configuration for EVE Online with no malicious patterns, exfiltration, or dangerous behavior detected. |
| providers/facebook.js | safe | This is a standard OAuth provider configuration for Facebook with no malicious patterns detected. |
| providers/freshbooks.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Freshbooks with no data exfiltration, credential harvesting, or dynamic code execution. |
| providers/fusionauth.js | safe | No malicious patterns detected; the file contains a standard OAuth provider configuration for FusionAuth with no exfiltration, code execution, or filesystem/network abuse. |
| providers/github.js | safe | No malicious patterns detected |
| providers/gitlab.js | safe | No malicious patterns detected |
| providers/google.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Google with no data exfiltration, credential harvesting, or dangerous code execution. |
| providers/hubspot.js | safe | This is a standard OAuth provider configuration for HubSpot with no malicious patterns detected. |
| providers/identity-server4.js | safe | No malicious patterns detected |
| providers/index.js | safe | No malicious patterns detected; this is a standard ES module re-export barrel file with no network, filesystem, or dynamic execution behavior. |
| providers/instagram.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Instagram with no network exfiltration, dynamic execution, or install-time behavior. |
| providers/kakao.js | safe | No malicious patterns detected in the Kakao OAuth provider configuration code. |
| providers/keycloak.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration file for Keycloak authentication. |
| providers/line.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for LINE with no suspicious behavior. |
| providers/linkedin.js | safe | This is a standard OAuth provider configuration file for LinkedIn authentication; no malicious patterns detected. |
| providers/mailchimp.js | safe | No malicious patterns detected; this is a benign OAuth provider configuration for Mailchimp. |
| providers/mailru.js | safe | No malicious patterns detected in the Mail.ru OAuth provider configuration. |
| providers/medium.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for Medium with no suspicious behavior. |
| providers/naver.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Naver. |
| providers/netlify.js | safe | No malicious patterns detected; the file is a clean OAuth provider configuration with no network, filesystem, or code-execution side effects. |
| providers/oauth.js | safe | No malicious patterns detected |
| providers/okta.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Okta with no data exfiltration, credential harvesting, or dynamic code execution. |
| providers/onelogin.js | safe | This is a standard OAuth/OIDC provider configuration for OneLogin with no malicious patterns, no dynamic code execution, no credential harvesting, and no network or file system manipulation beyond constructing a well-known configuration URL. |
| providers/osso.js | safe | No malicious patterns detected |
| providers/osu.js | safe | No malicious patterns detected |
| providers/passage.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Passage with no network, filesystem, or process manipulation. |
| providers/patreon.js | safe | No malicious patterns detected; this is a benign OAuth provider configuration for Patreon. |
| providers/pinterest.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Pinterest with no data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| providers/pipedrive.js | safe | No malicious patterns detected |
| providers/salesforce.js | safe | No malicious patterns detected |
| providers/slack.js | safe | This is a standard OAuth provider configuration for Slack with no malicious patterns detected. |
| providers/spotify.js | safe | No malicious patterns detected |
| providers/strava.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Strava with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns. |
| providers/todoist.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Todoist with expected API calls and no exfiltration, obfuscation, or suspicious behavior. |
| providers/trakt.js | safe | The Trakt OAuth provider implementation contains only expected, legitimate OAuth flow logic with no malicious patterns. |
| providers/twitch.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for Twitch with no external data handling or code execution. |
| providers/twitter.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Twitter with no data exfiltration, credential harvesting, or suspicious behavior. |
| providers/united-effects.js | safe | This is a standard NextAuth OAuth provider configuration for United Effects with no malicious patterns, network exfiltration, dynamic code execution, or credential harvesting. |
| providers/vk.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for VK with no exfiltration, obfuscation, or dynamic execution. |
| providers/wikimedia.js | safe | This is a standard OAuth provider configuration for Wikimedia with no malicious patterns detected. |
| providers/wordpress.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for WordPress.com with no network, filesystem, or process manipulation. |
| providers/workos.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for WorkOS with no data exfiltration, credential harvesting, or dynamic code execution. |
| providers/yandex.js | safe | This is a standard OAuth provider configuration for Yandex with no malicious patterns detected. |
| providers/zitadel.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for ZITADEL. |
| providers/zoho.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Zoho with no suspicious code. |
| providers/zoom.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Zoom with no data exfiltration, credential harvesting, or suspicious behavior. |
| react/types.js | safe | No malicious patterns detected |
| src/adapters.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/client/_utils.ts | safe | This file contains standard NextAuth client utility code for session fetching, base URL resolution, and cross-tab broadcasting; no exfiltration, credential harvesting, obfuscation, process spawning, or install-time hooks were found, with only minor informational concerns about cookie forwarding to configured base URLs and unguarded JSON parsing. |
| src/core/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/core/index.ts | safe | This is a legitimate NextAuth.js core handler file; no data exfiltration, credential harvesting, obfuscation, shell/process execution, or backdoor patterns were found. |
| src/core/init.ts | safe | No malicious patterns detected; the code is a standard authentication initialization module from NextAuth.js with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| src/core/lib/assert.ts | safe | The code is a configuration validator for next-auth; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning were detected. |
| src/core/lib/callback-handler.ts | safe | The code is a legitimate authentication callback handler with no malicious patterns, though it contains an intentionally risky opt-in account linking feature that is clearly documented and gated. |
| src/core/lib/callback-url.ts | safe | The code performs standard callback URL validation and cookie handling without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized execution. |
| src/core/lib/cookie.ts | safe | No malicious patterns detected; the code handles cookie chunking and session token storage for NextAuth with standard secure cookie options. |
| src/core/lib/csrf-token.ts | safe | This is a standard double-submit CSRF token implementation using Node.js crypto primitives with no malicious patterns, network calls, process spawning, or credential harvesting. |
| src/core/lib/default-callbacks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/core/lib/email/getUserFromEmail.ts | safe | No malicious patterns detected; the code only queries a user by email via the configured adapter and returns a placeholder object if not found, consistent with NextAuth/Auth.js behavior. |
| src/core/lib/email/signin.ts | safe | The code implements a standard email verification flow and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning; only minor token-in-URL exposure concerns typical of such flows were noted. |
| src/core/lib/oauth/authorization-url.ts | safe | No malicious patterns detected; the code is a standard OAuth authorization URL generator with no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious behavior. |
| src/core/lib/oauth/callback.ts | safe | No malicious patterns detected; this is a legitimate OAuth callback handler from NextAuth.js. |
| src/core/lib/oauth/checks.ts | safe | No malicious patterns detected; the code implements standard OAuth PKCE, state, and nonce cookie handling using signed JWTs with no external data exfiltration, process spawning, or dynamic code execution. |
| src/core/lib/oauth/client-legacy.ts | safe | No malicious patterns detected; the file only promisifies and wraps an OAuth 1.0 client library with a module-scoped token store. |
| src/core/lib/oauth/client.ts | safe | This is a legitimate OAuth/OIDC client initialization file with no malicious patterns; minor concerns relate to configuration trust and global state mutation inherent to its design. |
| src/core/lib/providers.ts | safe | No malicious patterns detected; the code only normalizes and merges OAuth provider configuration without any exfiltration, code execution, or filesystem/network abuse. |
| src/core/pages/index.ts | safe | The file contains only standard page-rendering logic for authentication pages, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning. |
| src/core/routes/callback.ts | safe | No malicious patterns detected; the code is a standard NextAuth.js OAuth/email/credentials callback handler with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| src/core/routes/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/core/routes/providers.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/core/routes/session.ts | safe | No malicious patterns detected; the file implements standard session handling for a NextAuth-like authentication library without external data exfiltration, credential harvesting, dynamic code execution, or other red flags. |
| src/core/routes/signin.ts | safe | No malicious patterns detected |
| src/core/routes/signout.ts | safe | No malicious patterns detected; this is a standard Auth.js signout route handler with no exfiltration, code execution, filesystem, network, or process manipulation concerns. |
| src/core/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/jwt/index.ts | safe | No malicious patterns detected; the code implements standard JWT encoding/decoding and token extraction for NextAuth.js without any data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| src/jwt/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/middleware.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/next/index.ts | safe | No malicious patterns detected |
| src/next/middleware.ts | safe | This is the legitimate NextAuth.js middleware implementation with no malicious patterns detected; it performs expected authentication checks, JWT validation, and redirects without any data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| src/next/utils.ts | safe | No malicious patterns detected; the code handles HTTP cookies and request/response body parsing without any exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| src/providers/42-school.ts | safe | This is a standard OAuth provider configuration file for 42 School with no malicious patterns, dynamic code execution, network exfiltration, or credential harvesting detected. |
| src/providers/apple.ts | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Apple sign-in. |
| src/providers/atlassian.ts | safe | This is a standard OAuth provider configuration for Atlassian with no malicious patterns detected. |
| src/providers/auth0.ts | safe | No malicious patterns detected; the code is a standard Auth0 OAuth provider configuration for NextAuth.js with no data exfiltration, credential harvesting, or dynamic code execution. |
| src/providers/authentik.ts | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Authentik with no exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| src/providers/azure-ad-b2c.ts | safe | No malicious patterns detected |
| src/providers/azure-ad.ts | safe | The code is a legitimate NextAuth.js Azure AD OAuth provider implementation with no malicious patterns detected. |
| src/providers/battlenet.ts | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Battle.net with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| src/providers/box.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Box with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| src/providers/boxyhq-saml.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for BoxHQ SAML with no exfiltration, credential harvesting, or dynamic execution. |
| src/providers/bungie.js | safe | No malicious patterns detected |
| src/providers/cognito.ts | safe | No malicious patterns detected |
| src/providers/coinbase.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Coinbase with no data exfiltration, credential harvesting, or dynamic execution. |
| src/providers/credentials.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/providers/discord.ts | safe | No malicious patterns detected |
| src/providers/dropbox.js | safe | No malicious patterns detected; the file is a standard NextAuth.js Dropbox OAuth provider configuration. |
| src/providers/duende-identity-server6.ts | safe | No malicious patterns detected |
| src/providers/email.ts | safe | No malicious patterns detected; the code is a standard NextAuth email provider using nodemailer to send verification emails with no exfiltration, obfuscation, or install-time execution. |
| src/providers/eveonline.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for EVE Online with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| src/providers/facebook.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Facebook with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| src/providers/faceit.js | safe | No malicious patterns detected |
| src/providers/foursquare.js | safe | No malicious patterns detected |
| src/providers/freshbooks.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Freshbooks. |
| src/providers/fusionauth.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for FusionAuth with no exfiltration, credential harvesting, or dynamic execution. |
| src/providers/github.ts | safe | No malicious patterns detected; the code is a standard GitHub OAuth provider implementation for NextAuth.js. |
| src/providers/gitlab.ts | safe | The GitLab OAuth provider configuration contains no malicious patterns; it only defines standard OAuth endpoints, profile mapping, and styling for a legitimate authentication integration. |
| src/providers/google.ts | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Google with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| src/providers/hubspot.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for HubSpot with only a minor security consideration regarding token placement in URL. |
| src/providers/identity-server4.js | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for IdentityServer4 with no exfiltration, code execution, or suspicious behavior. |
| src/providers/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/providers/instagram.js | safe | No malicious patterns detected; the file is a standard NextAuth OAuth provider configuration for Instagram with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns. |
| src/providers/kakao.ts | safe | This is a standard NextAuth.js Kakao OAuth provider configuration with no malicious patterns detected. |
| src/providers/keycloak.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Keycloak with no exfiltration, obfuscation, or suspicious behavior. |
| src/providers/line.ts | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for LINE authentication. |
| src/providers/linkedin.ts | safe | This is a standard NextAuth.js LinkedIn OAuth provider implementation with no malicious patterns, credential harvesting, or suspicious behavior. |
| src/providers/mailchimp.js | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Mailchimp with no suspicious code execution, data exfiltration, or credential harvesting. |
| src/providers/mailru.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Mail.ru. |
| src/providers/medium.js | safe | No malicious patterns detected |
| src/providers/naver.ts | safe | No malicious patterns detected; the file is a standard NextAuth Naver OAuth provider configuration with no data exfiltration, credential harvesting, dynamic execution, or suspicious network activity. |
| src/providers/netlify.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Netlify with only static URLs and a profile mapping function. |
| src/providers/oauth-types.ts | safe | This file contains only a static TypeScript union type declaration of OAuth provider names with no executable code, network activity, credential access, or other malicious patterns. |
| src/providers/oauth.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/providers/okta.ts | safe | This is a standard OAuth provider configuration for Okta with no malicious patterns, exfiltration, or suspicious behavior detected. |
| src/providers/onelogin.js | safe | The OneLogin OAuth provider configuration is a standard, benign NextAuth.js provider definition with no malicious patterns, dynamic code execution, credential harvesting, or network exfiltration. |
| src/providers/osso.js | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration with no network, filesystem, or dynamic code execution activities. |
| src/providers/osu.ts | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for osu! with no network exfiltration, credential harvesting, or dynamic code execution. |
| src/providers/passage.ts | safe | The file is a standard NextAuth Passsage OAuth provider configuration with no malicious patterns, no external data exfiltration, no credential harvesting, and no dynamic code execution. |
| src/providers/patreon.ts | safe | This is a standard OAuth provider configuration for Patreon with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. It only defines static OAuth endpoints and a profile mapping function. |
| src/providers/pinterest.ts | safe | This is a standard OAuth provider configuration for Pinterest with no malicious patterns, external data exfiltration, or dynamic code execution. |
| src/providers/pipedrive.ts | safe | No malicious patterns detected in the Pipedrive OAuth provider configuration. |
| src/providers/slack.ts | safe | No malicious patterns detected; this is a standard NextAuth Slack OAuth provider configuration with no data exfiltration, credential harvesting, or dynamic code execution. |
| src/providers/spotify.ts | safe | No malicious patterns detected; this is a standard NextAuth.js OAuth provider configuration for Spotify. |
| src/providers/strava.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Strava with no data exfiltration, dynamic code execution, or other security concerns. |
| src/providers/todoist.ts | safe | No malicious patterns detected; the Todoist OAuth provider code performs expected Todoist API calls for authentication and user info retrieval with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| src/providers/trakt.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for Trakt with expected network requests to trakt.tv APIs and no suspicious behavior. |
| src/providers/twitch.ts | safe | This is a standard OAuth provider configuration for Twitch with no malicious patterns, exfiltration, obfuscation, or suspicious behavior. |
| src/providers/twitter.ts | safe | The code is a standard OAuth provider implementation for Twitter (legacy and v2) with no malicious patterns, exfiltration, dynamic execution, or suspicious network activity. |
| src/providers/united-effects.ts | safe | No malicious patterns detected; this is a standard OAuth provider configuration for United Effects. |
| src/providers/vk.ts | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for VK with a large type definition and no dynamic execution, network exfiltration, or suspicious behavior. |
| src/providers/wikimedia.ts | safe | No malicious patterns detected; this is a standard OAuth provider configuration for Wikimedia with no exfiltration, credential harvesting, obfuscation, or process execution. |
| src/providers/wordpress.js | safe | No malicious patterns detected |
| src/providers/workos.ts | safe | No malicious patterns detected; this is a standard OAuth provider configuration for WorkOS with no data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| src/providers/yandex.ts | safe | No malicious patterns detected |
| src/providers/zitadel.ts | safe | No malicious patterns detected; the code is a standard OAuth provider configuration for ZITADEL with no exfiltration, credential harvesting, obfuscation, or other red flags. |
| src/providers/zoho.js | safe | No malicious patterns detected; the file is a standard OAuth provider configuration for Zoho. |
| src/providers/zoom.ts | safe | No malicious patterns detected; the file defines a standard OAuth provider configuration for Zoom with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network activity. |
| src/react/index.tsx | safe | No malicious patterns detected; the file is the legitimate NextAuth React client with expected auth-related fetch calls and no exfiltration, credential harvesting, obfuscation, or command execution. |
| src/react/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/detect-origin.ts | safe | No malicious patterns detected |
| src/utils/merge.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/parse-url.ts | safe | No malicious patterns detected; the code is a straightforward URL parsing utility with no network, filesystem, process execution, or obfuscation concerns. |
| utils/detect-origin.js | safe | No malicious patterns detected |
| utils/parse-url.js | safe | No malicious patterns detected |
Scanned versions of next-auth
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 4.24.15 | Needs review | 226 | Oct 6, 2026 |
Frequently asked questions
Is next-auth safe to use?
No confirmed malware was found in next-auth@4.24.15, but the review flagged 2 high, 23 medium, 40 low severity findings for risky patterns worth checking before you rely on it.
Does next-auth contain malware?
No malware was identified in next-auth@4.24.15 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was next-auth checked?
Togoder Security downloaded the published npm package and had an AI model read its 226 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan next-auth together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in next-auth@4.24.15, cost nothing.