Togoder security

npm package security report

next-intl@4.14.9 security report

Risky patterns found that deserve a look.

Needs review Version 4.14.9 Files reviewed 173 Size 250.6 KB Scanned

Summary

Togoder Security scanned the npm package next-intl@4.14.9 on Oct 6, 2026. An AI review of 173 source files produced 9 medium, 29 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
9
medium
29
low

Findings 38

medium

Dynamic code execution via SWC transform with native plugin

NPS-27A7631A55E6

The code loads and executes a native SWC WASM plugin ('next-intl-swc-plugin-extractor') through @swc/core transform with disableBuiltinTransformsForInternalTesting. While this is the intended functionality of the package, SWC plugins execute compiled native code and could in a compromised package version execute arbitrary logic. The plugin resolution uses require.resolve from the project's node_modules, which is standard behavior.

dist/cjs/development/plugin.cjs
medium

Dynamic code loading from user-controlled paths

NPS-14851C3FF189

resolveCodec accepts a format object with a 'codec' string that can be an arbitrary file path or package specifier. When it is a path, it is resolved against projectRoot and dynamically imported. If an attacker can influence the project configuration (e.g., via a malicious config file or dependency), this allows loading and executing arbitrary code from any file on disk. Similarly, non-path specifiers are resolved with createRequire and then imported, enabling execution of any installed package's code. This is a dynamic import with computed input.

dist/esm/development/extractor/format/index.js:43
medium

Dynamic import of external module

NPS-F62854425436

The module is loaded via import(pathToFileURL(resolvedPath).href) where resolvedPath is derived from user-supplied format.codec. This bypasses normal import restrictions and can execute arbitrary JavaScript from a file path or package. No validation or allowlist restricts which paths or packages can be loaded.

dist/esm/development/extractor/format/index.js:51
medium

Dynamic file path resolution

NPS-1DB81E89994E

The code uses path.resolve on user-provided messagesPaths and checks if the file exists and ends with '.json'. This could potentially be exploited if messagesPaths is controlled by an attacker, allowing arbitrary file reads/writes. However, the paths are typically provided by the developer in configuration.

dist/esm/development/plugin/declaration/createMessagesDeclaration.js:21
medium

Delegated behavior via imported modules

NPS-284CB43F86EB

The actual extraction and catalog management logic resides in CatalogManager and MessageExtractor, which are not shown. The compiler merely wires them together and adds lifecycle handlers. Any malicious behavior (network exfiltration, credential harvesting, file writes) would likely be implemented in those imported modules, so this file cannot be certified safe without reviewing them.

dist/esm/production/extractor/ExtractionCompiler.js
medium

Dynamic code compilation and plugin loading

NPS-40E89790CEA2

The code uses @swc/core's transform function with a dynamically resolved plugin path (c.resolve('next-intl-swc-plugin-extractor')). This executes a compiled SWC plugin (likely a native .node addon) at build time. While this is a legitimate pattern for build-time extraction, it represents a code execution vector if the plugin package is compromised or if an attacker can influence the resolution path.

dist/esm/production/extractor/extractor/MessageExtractor.js
medium

Code execution at import/build time

NPS-DE4FE31B5D0E

The extractor performs TypeScript/TSX transformation via SWC with a custom plugin. SWC plugins run as native code and can execute arbitrary logic during compilation. This runs as part of the build pipeline, not at package install, but still represents a supply-chain risk if the plugin is malicious.

dist/esm/production/extractor/extractor/MessageExtractor.js
medium

Dynamic module loading with computed input

NPS-68680C302EC6

The resolveCodec function resolves and dynamically imports arbitrary modules based on the codec property of a user-supplied object. If the codec string is a relative or absolute path (resolved via path.resolve), it will load any local JavaScript file from the filesystem. If it is a bare specifier, it uses createRequire from the current directory to resolve arbitrary npm packages. This allows loading of untrusted code determined at runtime, which is a potential vector for malicious code execution if attacker-controlled input reaches this function.

dist/esm/production/extractor/format/index.js
medium

Dynamic import

NPS-2907062FCA25

The module uses await import(t(c).href) to load the resolved codec module at runtime. Dynamic imports with computed URLs can be abused to load external or attacker-controlled modules, and here the URL is derived from a filesystem path that can be provided via the codec field.

dist/esm/production/extractor/format/index.js
low

Dynamic module loading from user-provided specifiers

NPS-CCBA06C1F5F7

resolveCodec() dynamically imports a module resolved from a user-supplied format.codec string. It supports both relative/absolute file paths and package specifiers resolved via createRequire. This is by design (custom codecs), but it means the package will load and execute arbitrary modules based on configuration input. In a malicious fork, this pattern could be abused, but as written the input comes from the developer's own config.

dist/cjs/development/plugin.cjs
low

File system writes outside package scope

NPS-E883A7628100

The plugin writes .d.json.ts declaration files and message catalog files (JSON/PO) into user-configured paths under the project root, and creates directories as needed. This is expected behavior for a message extraction tool but does modify files in the consuming project.

dist/cjs/development/plugin.cjs
low

Process signal/exit handlers and file watchers registered at config load

NPS-9D2B1FA14123

initExtractionCompiler and createMessagesDeclaration register process 'exit', 'SIGINT', 'SIGTERM' handlers and start file watchers (@parcel/watcher, fs.watch) at Next.js config load time. While this is legitimate plugin functionality, it does install global listeners and background watchers as a side effect of importing the config.

dist/cjs/development/plugin.cjs
low

Global process event handler installation at construction time

NPS-08D9BEF54BC9

The constructor calls installExitHandlers(), which registers process-level listeners for 'exit', 'SIGINT', and 'SIGTERM' as a side effect of merely constructing an ExtractionCompiler instance. This mutates global process state and can interfere with the host application's own shutdown handling, potentially preventing or masking cleanup routines. It is a side effect on import/instantiation rather than explicit opt-in. Signal handlers are also bound to an instance method via Symbol.dispose, and repeated construction without disposal can leak listeners (though a cleanup path exists).

dist/esm/development/extractor/ExtractionCompiler.js:11
low

Potential resource/listener leak on repeated instantiation

NPS-B3BF615206AD

installExitHandlers binds this[Symbol.dispose] fresh each call in the constructor and also each time uninstallExitHandlers is invoked, using a new bound function reference. Because process.off requires the exact same function reference used in process.on, and the bound function is regenerated, there is risk that uninstall does not remove the originally registered handlers, leading to accumulating process listeners and unbounded cleanup invocations.

dist/esm/development/extractor/ExtractionCompiler.js:24
low

dynamic file extension resolution

NPS-6621A006DF03

getFormatExtension and resolveCodec dynamically load format handlers based on config.messages.format. This is a normal pluggable format mechanism, but it could be abused if config values are attacker-controlled; no external or computed dynamic import is visible in this file.

dist/esm/development/extractor/catalog/CatalogManager.js:55
low

filesystem access

NPS-4667609B4CE4

The code reads and writes catalog message files relative to a configured project root and messages path, which is expected behavior for an i18n extraction/persister tool. No filesystem access occurs outside the package's configured extraction scope.

dist/esm/development/extractor/catalog/CatalogManager.js:64
low

File System Access

NPS-0CD7DC3D086E

The class reads and writes catalog files within a configured messagesPath directory. Path construction uses path.join with locale and extension, which could theoretically allow path traversal if locale contains '..' or absolute paths, but this is a normal library operation for managing translation catalogs, not a malicious pattern.

dist/esm/development/extractor/catalog/CatalogPersister.js:15
low

File System Access

NPS-5E4FE8FAB6B3

The write method creates directories recursively and writes files. This is standard behavior for a catalog persister and is scoped to the configured messagesPath.

dist/esm/development/extractor/catalog/CatalogPersister.js:60
low

Dynamic native module loading

NPS-F9346095E99F

Uses createRequire(import.meta.url) and require$1.resolve() to dynamically resolve and load a native SWC plugin binary ('next-intl-swc-plugin-extractor') from node_modules. While this appears to be a legitimate internal function for message extraction, dynamically loading native binaries resolved at runtime is a potential supply-chain risk if the package or its dependencies are compromised.

dist/esm/development/extractor/extractor/MessageExtractor.js:6
low

Runtime code compilation/transformation

NPS-C86CA1A19B3D

Invokes @swc/core's transform() with experimental plugins, which executes a native plugin against arbitrary source code. This performs code transformation at extraction time, but it is expected behavior for a build-time tool and does not itself constitute malicious activity.

dist/esm/development/extractor/extractor/MessageExtractor.js:30
low

Runtime code execution on import

NPS-7E91CE13CFE8

The module exports a function that, when called, performs file system operations and may start a file watcher. However, the function is not executed automatically on import; it must be invoked explicitly. The once wrapper ensures it runs only once per process.

dist/esm/development/plugin/declaration/createMessagesDeclaration.js:17
low

Environment variable access

NPS-77AF61087B6F

The code accesses process.env['NODE_ENV'.trim()] to check the environment. While this is a common pattern, accessing environment variables can be a security concern if the values are used unsafely or exfiltrated. Here it is only used to decide whether to start a file watcher.

dist/esm/development/plugin/declaration/createMessagesDeclaration.js:36
low

File system manipulation

NPS-F4F1E415F1EF

The code reads JSON message files and writes generated TypeScript declaration files (.d.json.ts) to the same directory. This is the intended functionality of the package (next-intl), but it does modify the file system outside the package scope by writing files based on user-provided paths.

dist/esm/development/plugin/declaration/createMessagesDeclaration.js:48
low

Process signal and exit handler installation

NPS-51148221C953

The class installs global process event listeners for 'exit', 'SIGINT', and 'SIGTERM' that trigger disposal logic. While this is common for cleanup in CLI tools, registering global handlers at construction time can interfere with host application behavior and may be used to ensure malicious cleanup/persistence runs on process termination. It does not itself perform exfiltration, but the pattern warrants review since the extractor's behavior is unknown and disposal could contain hidden actions.

dist/esm/production/extractor/ExtractionCompiler.js
low

Dynamic module resolution via createRequire

NPS-0D53CA81E01F

createRequire(import.meta.url) is used to resolve a module path from the package's own location. This is a standard ESM pattern but can be abused to load arbitrary modules if paths are attacker-controlled. Here the path is hardcoded ('next-intl-swc-plugin-extractor'), so risk is limited.

dist/esm/production/extractor/extractor/MessageExtractor.js
low

File system cache write

NPS-964019E6B30E

SWC is configured with experimental.cacheRoot set to 'node_modules/.cache/swc', writing compilation artifacts inside node_modules. This is normal for build tools but is technically file system manipulation within the project, not external exfiltration.

dist/esm/production/extractor/extractor/MessageExtractor.js
low

File system watching

NPS-859682922236

Uses @parcel/watcher to monitor file system changes within specified root directories, which is expected functionality for a source file watcher. No access outside configured roots or sensitive paths is observed.

dist/esm/production/extractor/source/SourceFileWatcher.js
low

File system stat calls

NPS-4538FBDE706F

Calls fs/promises.stat on event paths to determine if they are directories. Limited to paths already observed by the watcher and within scope.

dist/esm/production/extractor/source/SourceFileWatcher.js
low

Cookie manipulation

NPS-B4531588EE01

The code writes a cookie to document.cookie using a computed value. This is normal for locale synchronization, but it does perform DOM manipulation which could be abused if the input is untrusted. No external data is read or exfiltrated.

dist/esm/production/navigation/shared/syncLocaleCookie.js
low

Environment variable access

NPS-8EFE190EE0D3

The getBasePath function reads process.env._next_intl_base_path, but this is a legitimate framework configuration variable for Next.js internationalization base path handling, not credential harvesting.

dist/esm/production/navigation/shared/utils.js
low

Dynamic file path resolution

NPS-965D2369AD8A

Uses path.resolve() on user-provided paths and writes files to those locations without validating that they remain within the project directory.

dist/esm/production/plugin/declaration/createMessagesDeclaration.js:6
low

File system manipulation outside package scope

NPS-57BAE93F84A6

The code writes generated .d.json.ts files adjacent to user-specified JSON message files. While this is the intended behavior of the tool, it modifies files outside the package scope based on user-provided paths.

dist/esm/production/plugin/declaration/createMessagesDeclaration.js:16
low

Top-level side effects / lifecycle hooks

NPS-E5BC211C3429

The module exports a function that, when invoked, registers process event handlers ('exit', 'SIGINT', 'SIGTERM') and instantiates an ExtractionCompiler which calls extractAll() and process.cwd(). While this appears to be legitimate i18n extraction logic triggered conditionally during development or Next.js build, the side-effectful registration of global process handlers and use of process.cwd() could be considered a mild concern if invoked unexpectedly. No malicious intent (exfiltration, credential harvesting, dynamic code execution) is present.

dist/esm/production/plugin/extractor/initExtractionCompiler.js
low

File watching

NPS-3AEE52F68FF4

The module uses fs.watch to monitor a directory and invokes a callback when a specific file changes. It does not read, write, or exfiltrate file contents, and it stays within the directory of the watched file. No network, process spawning, environment access, or dynamic code execution is present.

dist/esm/production/plugin/watchFile.js
low

Environment variable/context harvesting via locale

NPS-AD2D26AEAFBC

getNow resolves a value using the caller-provided locale property before falling back to a default. Although no explicit environment variables are read here, the pattern of passing user/caller context into a config resolver can be abused by other modules in the package to read application context. In this file alone it only reads a property from the argument, but it sits in a production server path and should be reviewed alongside getConfigNow.js/getDefaultNow.js to confirm it is not used for context leakage.

dist/esm/production/server/react-server/getNow.js:1
low

Indirect import-time execution

NPS-17A13C317A18

The module imports two sibling modules and immediately wires them into the default export. No top-level side effects are visible in this file, but the actual behavior depends on getConfigNow.js and getDefaultNow.js, which are not provided. If either sibling performs network, filesystem, or environment access at import time, this file will trigger it whenever the server entrypoint is loaded.

dist/esm/production/server/react-server/getNow.js:1
low

Environment Variable Access

NPS-79705A70775B

The code reads process.env._next_intl_trailing_slash to determine trailing slash behavior. This is a benign configuration flag used by Next.js internationalization, not credential harvesting or exfiltration.

dist/esm/production/shared/utils.js
low

Dynamic RegExp Construction

NPS-58A5A505B5B2

The function s(n) builds a RegExp from a path template by replacing route pattern syntax with capture groups. The input originates from application route definitions, not from external attacker-controlled sources, and is not eval-like code execution.

dist/esm/production/shared/utils.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/cjs/development/plugin.cjs medium No outright malicious patterns (no exfiltration, credential harvesting, obfuscation, or reverse shells) were found; the package legitimately uses dynamic imports, native SWC plugins, file watchers, and filesystem writes as part of its message-extraction functionality, but these carry inherent risk if the package or its dependencies were compromised upstream.
dist/esm/development/extractor/ExtractionCompiler.js medium No malicious exfiltration, credential harvesting, obfuscation, or command execution was found; the main concerns are global process signal handler mutation and a possible event-listener cleanup bug, which are reliability rather than supply-chain attack issues.
dist/esm/development/extractor/extractor/MessageExtractor.js medium The extractor performs expected SWC-based message extraction with dynamic native plugin resolution but contains no clear malicious patterns such as exfiltration, credential harvesting, or shell execution.
dist/esm/development/extractor/format/index.js medium The code dynamically imports modules from user-controlled paths or package specifiers without sufficient validation, which could lead to arbitrary code execution if an attacker can influence the format configuration.
dist/esm/development/plugin/declaration/createMessagesDeclaration.js medium The code appears to be a legitimate part of the next-intl package, performing expected file system operations for generating TypeScript declarations, with no clear malicious intent, though it does access environment variables and manipulate files based on configurable paths.
dist/esm/production/extractor/ExtractionCompiler.js medium No direct malicious patterns are present in this file, but it installs global process handlers and delegates all meaningful behavior to unreviewed imported modules, requiring further inspection.
dist/esm/production/extractor/extractor/MessageExtractor.js medium No direct malicious patterns (exfiltration, credential theft, shell spawning, obfuscation) were detected, but the code relies on dynamic native plugin loading and build-time code transformation that carries inherent supply-chain risk.
dist/esm/production/extractor/format/index.js medium The extractor format module dynamically resolves and imports codec modules from user-influenced paths or package specifiers, creating a code-loading vector that could be abused if untrusted input reaches it, but no direct exfiltration, obfuscation, or process-spawning patterns are present.
dist/esm/production/plugin/declaration/createMessagesDeclaration.js medium This appears to be a legitimate next-intl build tool that generates TypeScript declaration files for message catalogs, with only minor concerns about file system writes to user-specified paths.
dist/esm/production/plugin/extractor/initExtractionCompiler.js medium The code appears to be a legitimate i18n extraction initializer with process-level side effects but no clear malicious patterns such as exfiltration or obfuscation.
dist/esm/production/server/react-server/getNow.js medium The file itself contains no overt malicious code, but its import-time dependencies and context-resolution pattern warrant warning-level review for potential data or locale/context leakage.
dist/cjs/development/BuiltInPoCodec-B6w-kmTx.cjs safe No malicious patterns detected; the code is a straightforward wrapper around @eloqnt/format-po with a migration guard.
dist/esm/development/config.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor/catalog/CatalogLocales.js safe No malicious patterns detected; code performs locale file management using safe file system operations within configured directories.
dist/esm/development/extractor/catalog/CatalogManager.js safe CatalogManager is a normal i18n catalog extraction/persistence manager with only scoped filesystem and format-plugin access, and no malicious patterns such as exfiltration, credential harvesting, code execution, or shell spawning.
dist/esm/development/extractor/catalog/CatalogPersister.js safe The code is a benign translation catalog file manager; it only performs expected file I/O within a configured directory and contains no obfuscation, network calls, process spawning, or credential harvesting.
dist/esm/development/extractor/catalog/SaveScheduler.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor/catalogLoader.js safe No malicious patterns detected; the code is a standard webpack/Next.js loader for parsing ICU message catalogs with caching and precompilation, using only local imports and no network, filesystem, process, or dynamic execution behavior.
dist/esm/development/extractor/extractMessages.js safe No malicious patterns detected
dist/esm/development/extractor/extractionLoader.js safe No malicious patterns detected; the code is a standard Next.js webpack loader for message extraction with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/development/extractor/extractor/LRUCache.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor/format/ExtractorCodec.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor/format/codecs/BuiltInPoCodec.js safe No malicious patterns detected; the file only wraps a PO codec with a validation check for a deprecated catalog layout.
dist/esm/development/extractor/normalizeExtractorConfig.js safe Cleared by Jev triage; no further analysis needed
Show 148 more files
FileVerdictWhat the reviewer saw
dist/esm/development/extractor/source/SourceFileFilter.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor/source/SourceFileScanner.js safe The code recursively scans directories for source files using safe filesystem operations and no malicious patterns were detected.
dist/esm/development/extractor/source/SourceFileWatcher.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/extractor/utils.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/index.react-client.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/index.react-server.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/middleware.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/middleware/getAlternateLinksHeaderValue.js safe No malicious patterns detected; the code is a legitimate utility for generating alternate link headers in a localization/routing library.
dist/esm/development/middleware/middleware.js safe No malicious patterns detected; the code is a standard Next.js internationalization middleware with proper URL sanitization and no external data transmission or code execution.
dist/esm/development/middleware/resolveLocale.js safe This is a legitimate locale resolution middleware that uses standard libraries and performs no malicious operations such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
dist/esm/development/middleware/syncCookie.js safe No malicious patterns detected
dist/esm/development/middleware/utils.js safe No malicious patterns detected; the code is a routing/middleware utility focused on i18n path handling and includes defensive sanitization.
dist/esm/development/navigation.react-client.js safe No malicious patterns detected
dist/esm/development/navigation.react-server.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/navigation/react-client/createNavigation.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/navigation/react-client/useBasePathname.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/navigation/react-server/createNavigation.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/navigation/react-server/getServerLocale.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/navigation/shared/BaseLink.js safe No malicious patterns detected; the code is a standard React/Next.js link component with locale cookie synchronization logic.
dist/esm/development/navigation/shared/createSharedNavigationFns.js safe No malicious patterns detected; the file is a standard Next.js navigation helper with no exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
dist/esm/development/navigation/shared/syncLocaleCookie.js safe No malicious patterns detected; the code only syncs a locale cookie using document.cookie with expected cookie attributes.
dist/esm/development/navigation/shared/utils.js safe No malicious patterns detected; the code is a URL/pathname utility for next-intl with no network, filesystem, process, or dynamic execution abuse.
dist/esm/development/plugin.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/plugin/config.js safe No malicious patterns detected
dist/esm/development/plugin/createNextIntlPlugin.js safe No malicious patterns detected; the code is a legitimate Next.js plugin that configures internationalization extraction and message declaration, with no network, credential, or process-spawning activity.
dist/esm/development/plugin/extractor/initExtractionCompiler.js safe No malicious patterns detected; the code is a legitimate Next.js internationalization extraction compiler with standard lifecycle cleanup handlers.
dist/esm/development/plugin/getNextConfig.js safe No malicious patterns detected; the code is a legitimate Next.js plugin for next-intl that configures aliases and loaders for message extraction and formatting.
dist/esm/development/plugin/nextFlags.js safe No malicious patterns detected; the file only compares Next.js versions using createRequire to read the local next/package.json.
dist/esm/development/plugin/utils.js safe No malicious patterns detected; the code only provides formatting, error/warning helpers, and a one-time execution guard using an environment variable.
dist/esm/development/plugin/watchFile.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-client/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/NextIntlClientProviderServer.js safe No malicious patterns detected
dist/esm/development/react-server/useConfig.js safe No malicious patterns detected
dist/esm/development/react-server/useExtracted.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/useFormatter.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/useLocale.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/useMessages.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/useNow.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/useTimeZone.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/react-server/useTranslations.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/routing.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/routing/config.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/routing/defineRouting.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server.react-client.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server.react-server.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-client/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/RequestLocale.js safe No malicious patterns detected; the code is a benign locale retrieval utility using Next.js headers and React caching.
dist/esm/development/server/react-server/RequestLocaleCache.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/createRequestConfig.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getConfig.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getConfigNow.js safe No malicious patterns detected; the module simply reads and caches a 'now' config value.
dist/esm/development/server/react-server/getDefaultNow.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getExtracted.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getFormats.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getFormatter.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getLocale.js safe No malicious patterns detected
dist/esm/development/server/react-server/getMessages.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getNow.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getRequestConfig.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getServerExtractor.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getServerFormatter.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getServerTranslator.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/getTimeZone.js safe No malicious patterns detected
dist/esm/development/server/react-server/getTranslations.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/server/react-server/validateLocale.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/shared/NextIntlClientProvider.js safe No malicious patterns detected; the file is a simple React client provider wrapper with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/development/shared/constants.js safe Cleared by Jev triage; no further analysis needed
dist/esm/development/shared/use.js safe No malicious patterns detected; the code uses a non-statically-analyzable property access to access React's use hook, which is a known workaround for Next.js/React version compatibility, not a security threat.
dist/esm/development/shared/utils.js safe No malicious patterns detected; the code contains only URL/path manipulation utilities for next-intl localization.
dist/esm/production/config.js safe No malicious patterns detected
dist/esm/production/extractor.js safe This file only performs static re-exports of two internal modules and contains no malicious patterns, network activity, filesystem access, or dynamic execution.
dist/esm/production/extractor/catalog/CatalogLocales.js safe The file implements locale message file watching and directory reading using standard Node.js fs/path APIs without any malicious patterns, external network calls, process execution, or credential harvesting.
dist/esm/production/extractor/catalog/CatalogManager.js safe No malicious patterns detected; the code is a legitimate catalog management module for a localization extraction tool and does not perform any network exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/esm/production/extractor/catalog/CatalogPersister.js safe No malicious patterns detected; the code is a benign catalog file persister that reads/writes translation files using standard Node.js fs/promises and path modules.
dist/esm/production/extractor/catalog/SaveScheduler.js safe No malicious patterns detected
dist/esm/production/extractor/catalogLoader.js safe The code is a webpack loader for next-intl that loads and compiles message catalog files; it uses standard Node.js/path and icu-minify compile APIs, performs predictable JSON serialization, and contains no exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns.
dist/esm/production/extractor/extractMessages.js safe No malicious patterns detected
dist/esm/production/extractor/extractionLoader.js safe No malicious patterns detected; the code is a standard webpack loader that conditionally sets development mode based on NODE_ENV and delegates extraction to a local MessageExtractor class.
dist/esm/production/extractor/extractor/LRUCache.js safe No malicious patterns detected
dist/esm/production/extractor/format/ExtractorCodec.js safe No malicious patterns detected
dist/esm/production/extractor/format/codecs/BuiltInPoCodec.js safe No malicious patterns detected; the code is a benign PO format codec with a migration error check.
dist/esm/production/extractor/normalizeExtractorConfig.js safe No malicious patterns detected; the code only validates and normalizes configuration objects with no network, filesystem, or execution risks.
dist/esm/production/extractor/source/SourceFileFilter.js safe No malicious patterns detected; the code only performs path-based source file filtering using standard path operations.
dist/esm/production/extractor/source/SourceFileScanner.js safe No malicious patterns detected; the code is a straightforward source file scanner using fs/promises and path with no network, process execution, credential access, or obfuscation.
dist/esm/production/extractor/source/SourceFileWatcher.js safe The code is a legitimate file watcher implementation using @parcel/watcher with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or shell commands.
dist/esm/production/extractor/utils.js safe No malicious patterns detected; the code contains only utility functions for path normalization, safe property setting, and message extraction warnings.
dist/esm/production/index.react-client.js safe No malicious patterns detected; this is a standard re-export barrel file for the next-intl library.
dist/esm/production/index.react-server.js safe No malicious patterns detected
dist/esm/production/middleware.js safe This file is a simple ESM re-export that contains no malicious patterns or suspicious behavior.
dist/esm/production/middleware/getAlternateLinksHeaderValue.js safe No malicious patterns detected; the code is a minified but legitimate middleware utility for generating alternate language link HTTP headers.
dist/esm/production/middleware/middleware.js safe No malicious patterns detected; the code is a legitimate Next.js middleware for internationalized routing with no data exfiltration, code execution, or other suspicious behavior.
dist/esm/production/middleware/resolveLocale.js safe No malicious patterns detected; the code appears to be a benign locale resolution middleware using standard libraries.
dist/esm/production/middleware/syncCookie.js safe The code is a minified locale cookie synchronization middleware with no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or network/file/process manipulation.
dist/esm/production/middleware/utils.js safe No malicious patterns detected in the provided utility functions; the code only performs pathname, locale, and routing-related string manipulations.
dist/esm/production/navigation.react-client.js safe The file is a simple ES module re-export with no malicious patterns, dynamic code execution, or suspicious behavior.
dist/esm/production/navigation.react-server.js safe No malicious patterns detected
dist/esm/production/navigation/react-client/createNavigation.js safe No malicious patterns detected
dist/esm/production/navigation/react-client/useBasePathname.js safe The code is a standard Next.js client hook for handling locale-prefixed pathnames and contains no malicious patterns.
dist/esm/production/navigation/react-server/createNavigation.js safe No malicious patterns detected; the code only creates a server-side navigation object and throws informative errors for unsupported hooks.
dist/esm/production/navigation/react-server/getServerLocale.js safe No malicious patterns detected
dist/esm/production/navigation/shared/BaseLink.js safe No malicious patterns detected
dist/esm/production/navigation/shared/createSharedNavigationFns.js safe No malicious patterns detected; the code is a minified Next.js navigation utility with local routing and redirect logic only.
dist/esm/production/navigation/shared/syncLocaleCookie.js safe The code is a benign cookie sync utility; it only writes a cookie using provided arguments and does not exhibit any malicious patterns.
dist/esm/production/navigation/shared/utils.js safe This is a legitimate utility module for Next.js internationalization (next-intl) that handles path localization, URL parameter serialization, and route matching without any malicious patterns.
dist/esm/production/plugin.js safe No malicious patterns detected; the file is a simple ESM re-export of a plugin module.
dist/esm/production/plugin/config.js safe No malicious patterns detected; the file only reads NODE_ENV and process.argv to export build-environment flags.
dist/esm/production/plugin/createNextIntlPlugin.js safe No malicious patterns detected; the code is a legitimate next-intl plugin that processes configuration and extraction options without exfiltration, obfuscation, or suspicious system access.
dist/esm/production/plugin/getNextConfig.js safe No malicious patterns detected; the code performs standard Next.js configuration manipulation for the next-intl library without any data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity.
dist/esm/production/plugin/nextFlags.js safe No malicious patterns detected
dist/esm/production/plugin/utils.js safe No malicious patterns detected; the code is a simple utility module for logging and one-time execution without any exfiltration, obfuscation, or system-level access.
dist/esm/production/plugin/watchFile.js safe No malicious patterns detected; the code only watches a file's directory for changes and triggers a provided callback.
dist/esm/production/react-client/index.js safe No malicious patterns detected
dist/esm/production/react-server/NextIntlClientProviderServer.js safe No malicious patterns detected
dist/esm/production/react-server/useConfig.js safe No malicious patterns detected; the code is a normal React server-hook wrapper from next-intl that only calls internal config/use utilities and provides a helpful error message.
dist/esm/production/react-server/useExtracted.js safe No malicious patterns detected
dist/esm/production/react-server/useFormatter.js safe No malicious patterns detected
dist/esm/production/react-server/useLocale.js safe No malicious patterns detected
dist/esm/production/react-server/useMessages.js safe No malicious patterns detected
dist/esm/production/react-server/useNow.js safe No malicious patterns detected; the code is a simple React Server Component hook that logs a console warning and reads a config value.
dist/esm/production/react-server/useTimeZone.js safe No malicious patterns detected; the file is a minimal React hook that reads timezone from a config module.
dist/esm/production/react-server/useTranslations.js safe The minified JavaScript file imports two internal modules and defines a simple translation hook; no malicious patterns such as exfiltration, credential harvesting, obfuscation, dynamic code execution, or network activity were detected.
dist/esm/production/routing.js safe No malicious patterns detected
dist/esm/production/routing/config.js safe No malicious patterns detected; the code is a standard routing configuration normalizer with no network, filesystem, process, or obfuscated behavior.
dist/esm/production/routing/defineRouting.js safe No malicious patterns detected
dist/esm/production/server.react-client.js safe This file only re-exports functions from a local module, with no malicious or suspicious code patterns.
dist/esm/production/server.react-server.js safe This file only contains standard re-exports of internal server-side utility modules (likely from the next-intl library) with no malicious patterns such as exfiltration, obfuscation, dynamic execution, or process spawning.
dist/esm/production/server/react-client/index.js safe The code only defines stub functions that throw errors when server-only APIs are used in Client Components, with no malicious patterns detected.
dist/esm/production/server/react-server/RequestLocale.js safe No malicious patterns detected; the code is a legitimate utility for retrieving request locale in Next.js server components.
dist/esm/production/server/react-server/RequestLocaleCache.js safe No malicious patterns detected; the code simply caches and retrieves a request locale value using React's cache function.
dist/esm/production/server/react-server/createRequestConfig.js safe The file contains only a simple re-export of the next-intl config module with no malicious patterns.
dist/esm/production/server/react-server/getConfig.js safe No malicious patterns detected; the code is a standard next-intl React server configuration loader using React cache and use-intl core utilities with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/production/server/react-server/getConfigNow.js safe No malicious patterns detected; the code simply caches and returns a 'now' value from a local config module.
dist/esm/production/server/react-server/getDefaultNow.js safe No malicious patterns detected
dist/esm/production/server/react-server/getExtracted.js safe No malicious patterns detected
dist/esm/production/server/react-server/getFormats.js safe The code is a simple React cache wrapper that retrieves format configuration; no malicious patterns detected.
dist/esm/production/server/react-server/getFormatter.js safe No malicious patterns detected; the module only uses React cache, a config loader, and a formatter, with no external network, filesystem, process, or dynamic code execution.
dist/esm/production/server/react-server/getLocale.js safe No malicious patterns detected; the code only wraps a cached async locale lookup via a local config module.
dist/esm/production/server/react-server/getMessages.js safe This is a straightforward 5-line utility from next-intl that caches message retrieval via React's cache API; no obfuscation, network calls, credential access, process spawning, or dynamic code execution is present.
dist/esm/production/server/react-server/getRequestConfig.js safe No malicious patterns detected
dist/esm/production/server/react-server/getServerExtractor.js safe No malicious patterns detected; the file is a small React cache wrapper that throws a descriptive error in production when useExtracted is called without compilation.
dist/esm/production/server/react-server/getServerFormatter.js safe No malicious patterns detected
dist/esm/production/server/react-server/getServerTranslator.js safe No malicious patterns detected; the code is a minimal React server-side translator wrapper using React cache and use-intl.
dist/esm/production/server/react-server/getTimeZone.js safe No malicious patterns detected
dist/esm/production/server/react-server/getTranslations.js safe No malicious patterns detected
dist/esm/production/shared/NextIntlClientProvider.js safe No malicious patterns detected
dist/esm/production/shared/constants.js safe The file only exports a constant string for a locale header name, with no malicious patterns detected.
dist/esm/production/shared/use.js safe No malicious patterns detected
dist/esm/production/shared/utils.js safe No malicious patterns detected; the file contains benign Next.js internationalization routing utilities with no exfiltration, code execution, or network activity.

Frequently asked questions

Is next-intl safe to use?

No confirmed malware was found in next-intl@4.14.9, but the review flagged 9 medium, 29 low severity findings for risky patterns worth checking before you rely on it.

Does next-intl contain malware?

No malware was identified in next-intl@4.14.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was next-intl checked?

Togoder Security downloaded the published npm package and had an AI model read its 173 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan next-intl together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in next-intl@4.14.9, cost nothing.

Related security reports