Summary
Togoder Security scanned the npm package next-intl@4.14.9 on Oct 6, 2026. An AI review of 173 source files produced 9 medium, 29 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 38
Dynamic code execution via SWC transform with native plugin
NPS-27A7631A55E6
The code loads and executes a native SWC WASM plugin ('next-intl-swc-plugin-extractor') through @swc/core transform with disableBuiltinTransformsForInternalTesting. While this is the intended functionality of the package, SWC plugins execute compiled native code and could in a compromised package version execute arbitrary logic. The plugin resolution uses require.resolve from the project's node_modules, which is standard behavior.
Dynamic code loading from user-controlled paths
NPS-14851C3FF189
resolveCodec accepts a format object with a 'codec' string that can be an arbitrary file path or package specifier. When it is a path, it is resolved against projectRoot and dynamically imported. If an attacker can influence the project configuration (e.g., via a malicious config file or dependency), this allows loading and executing arbitrary code from any file on disk. Similarly, non-path specifiers are resolved with createRequire and then imported, enabling execution of any installed package's code. This is a dynamic import with computed input.
Dynamic import of external module
NPS-F62854425436
The module is loaded via import(pathToFileURL(resolvedPath).href) where resolvedPath is derived from user-supplied format.codec. This bypasses normal import restrictions and can execute arbitrary JavaScript from a file path or package. No validation or allowlist restricts which paths or packages can be loaded.
Dynamic file path resolution
NPS-1DB81E89994E
The code uses path.resolve on user-provided messagesPaths and checks if the file exists and ends with '.json'. This could potentially be exploited if messagesPaths is controlled by an attacker, allowing arbitrary file reads/writes. However, the paths are typically provided by the developer in configuration.
Delegated behavior via imported modules
NPS-284CB43F86EB
The actual extraction and catalog management logic resides in CatalogManager and MessageExtractor, which are not shown. The compiler merely wires them together and adds lifecycle handlers. Any malicious behavior (network exfiltration, credential harvesting, file writes) would likely be implemented in those imported modules, so this file cannot be certified safe without reviewing them.
Dynamic code compilation and plugin loading
NPS-40E89790CEA2
The code uses @swc/core's transform function with a dynamically resolved plugin path (c.resolve('next-intl-swc-plugin-extractor')). This executes a compiled SWC plugin (likely a native .node addon) at build time. While this is a legitimate pattern for build-time extraction, it represents a code execution vector if the plugin package is compromised or if an attacker can influence the resolution path.
Code execution at import/build time
NPS-DE4FE31B5D0E
The extractor performs TypeScript/TSX transformation via SWC with a custom plugin. SWC plugins run as native code and can execute arbitrary logic during compilation. This runs as part of the build pipeline, not at package install, but still represents a supply-chain risk if the plugin is malicious.
Dynamic module loading with computed input
NPS-68680C302EC6
The resolveCodec function resolves and dynamically imports arbitrary modules based on the codec property of a user-supplied object. If the codec string is a relative or absolute path (resolved via path.resolve), it will load any local JavaScript file from the filesystem. If it is a bare specifier, it uses createRequire from the current directory to resolve arbitrary npm packages. This allows loading of untrusted code determined at runtime, which is a potential vector for malicious code execution if attacker-controlled input reaches this function.
Dynamic import
NPS-2907062FCA25
The module uses await import(t(c).href) to load the resolved codec module at runtime. Dynamic imports with computed URLs can be abused to load external or attacker-controlled modules, and here the URL is derived from a filesystem path that can be provided via the codec field.
Dynamic module loading from user-provided specifiers
NPS-CCBA06C1F5F7
resolveCodec() dynamically imports a module resolved from a user-supplied format.codec string. It supports both relative/absolute file paths and package specifiers resolved via createRequire. This is by design (custom codecs), but it means the package will load and execute arbitrary modules based on configuration input. In a malicious fork, this pattern could be abused, but as written the input comes from the developer's own config.
File system writes outside package scope
NPS-E883A7628100
The plugin writes .d.json.ts declaration files and message catalog files (JSON/PO) into user-configured paths under the project root, and creates directories as needed. This is expected behavior for a message extraction tool but does modify files in the consuming project.
Process signal/exit handlers and file watchers registered at config load
NPS-9D2B1FA14123
initExtractionCompiler and createMessagesDeclaration register process 'exit', 'SIGINT', 'SIGTERM' handlers and start file watchers (@parcel/watcher, fs.watch) at Next.js config load time. While this is legitimate plugin functionality, it does install global listeners and background watchers as a side effect of importing the config.
Global process event handler installation at construction time
NPS-08D9BEF54BC9
The constructor calls installExitHandlers(), which registers process-level listeners for 'exit', 'SIGINT', and 'SIGTERM' as a side effect of merely constructing an ExtractionCompiler instance. This mutates global process state and can interfere with the host application's own shutdown handling, potentially preventing or masking cleanup routines. It is a side effect on import/instantiation rather than explicit opt-in. Signal handlers are also bound to an instance method via Symbol.dispose, and repeated construction without disposal can leak listeners (though a cleanup path exists).
Potential resource/listener leak on repeated instantiation
NPS-B3BF615206AD
installExitHandlers binds this[Symbol.dispose] fresh each call in the constructor and also each time uninstallExitHandlers is invoked, using a new bound function reference. Because process.off requires the exact same function reference used in process.on, and the bound function is regenerated, there is risk that uninstall does not remove the originally registered handlers, leading to accumulating process listeners and unbounded cleanup invocations.
dynamic file extension resolution
NPS-6621A006DF03
getFormatExtension and resolveCodec dynamically load format handlers based on config.messages.format. This is a normal pluggable format mechanism, but it could be abused if config values are attacker-controlled; no external or computed dynamic import is visible in this file.
filesystem access
NPS-4667609B4CE4
The code reads and writes catalog message files relative to a configured project root and messages path, which is expected behavior for an i18n extraction/persister tool. No filesystem access occurs outside the package's configured extraction scope.
File System Access
NPS-0CD7DC3D086E
The class reads and writes catalog files within a configured messagesPath directory. Path construction uses path.join with locale and extension, which could theoretically allow path traversal if locale contains '..' or absolute paths, but this is a normal library operation for managing translation catalogs, not a malicious pattern.
File System Access
NPS-5E4FE8FAB6B3
The write method creates directories recursively and writes files. This is standard behavior for a catalog persister and is scoped to the configured messagesPath.
Dynamic native module loading
NPS-F9346095E99F
Uses createRequire(import.meta.url) and require$1.resolve() to dynamically resolve and load a native SWC plugin binary ('next-intl-swc-plugin-extractor') from node_modules. While this appears to be a legitimate internal function for message extraction, dynamically loading native binaries resolved at runtime is a potential supply-chain risk if the package or its dependencies are compromised.
Runtime code compilation/transformation
NPS-C86CA1A19B3D
Invokes @swc/core's transform() with experimental plugins, which executes a native plugin against arbitrary source code. This performs code transformation at extraction time, but it is expected behavior for a build-time tool and does not itself constitute malicious activity.
Runtime code execution on import
NPS-7E91CE13CFE8
The module exports a function that, when called, performs file system operations and may start a file watcher. However, the function is not executed automatically on import; it must be invoked explicitly. The once wrapper ensures it runs only once per process.
Environment variable access
NPS-77AF61087B6F
The code accesses process.env['NODE_ENV'.trim()] to check the environment. While this is a common pattern, accessing environment variables can be a security concern if the values are used unsafely or exfiltrated. Here it is only used to decide whether to start a file watcher.
File system manipulation
NPS-F4F1E415F1EF
The code reads JSON message files and writes generated TypeScript declaration files (.d.json.ts) to the same directory. This is the intended functionality of the package (next-intl), but it does modify the file system outside the package scope by writing files based on user-provided paths.
Process signal and exit handler installation
NPS-51148221C953
The class installs global process event listeners for 'exit', 'SIGINT', and 'SIGTERM' that trigger disposal logic. While this is common for cleanup in CLI tools, registering global handlers at construction time can interfere with host application behavior and may be used to ensure malicious cleanup/persistence runs on process termination. It does not itself perform exfiltration, but the pattern warrants review since the extractor's behavior is unknown and disposal could contain hidden actions.
Dynamic module resolution via createRequire
NPS-0D53CA81E01F
createRequire(import.meta.url) is used to resolve a module path from the package's own location. This is a standard ESM pattern but can be abused to load arbitrary modules if paths are attacker-controlled. Here the path is hardcoded ('next-intl-swc-plugin-extractor'), so risk is limited.
File system cache write
NPS-964019E6B30E
SWC is configured with experimental.cacheRoot set to 'node_modules/.cache/swc', writing compilation artifacts inside node_modules. This is normal for build tools but is technically file system manipulation within the project, not external exfiltration.
File system watching
NPS-859682922236
Uses @parcel/watcher to monitor file system changes within specified root directories, which is expected functionality for a source file watcher. No access outside configured roots or sensitive paths is observed.
File system stat calls
NPS-4538FBDE706F
Calls fs/promises.stat on event paths to determine if they are directories. Limited to paths already observed by the watcher and within scope.
Cookie manipulation
NPS-B4531588EE01
The code writes a cookie to document.cookie using a computed value. This is normal for locale synchronization, but it does perform DOM manipulation which could be abused if the input is untrusted. No external data is read or exfiltrated.
Environment variable access
NPS-8EFE190EE0D3
The getBasePath function reads process.env._next_intl_base_path, but this is a legitimate framework configuration variable for Next.js internationalization base path handling, not credential harvesting.
Dynamic file path resolution
NPS-965D2369AD8A
Uses path.resolve() on user-provided paths and writes files to those locations without validating that they remain within the project directory.
File system manipulation outside package scope
NPS-57BAE93F84A6
The code writes generated .d.json.ts files adjacent to user-specified JSON message files. While this is the intended behavior of the tool, it modifies files outside the package scope based on user-provided paths.
Top-level side effects / lifecycle hooks
NPS-E5BC211C3429
The module exports a function that, when invoked, registers process event handlers ('exit', 'SIGINT', 'SIGTERM') and instantiates an ExtractionCompiler which calls extractAll() and process.cwd(). While this appears to be legitimate i18n extraction logic triggered conditionally during development or Next.js build, the side-effectful registration of global process handlers and use of process.cwd() could be considered a mild concern if invoked unexpectedly. No malicious intent (exfiltration, credential harvesting, dynamic code execution) is present.
File watching
NPS-3AEE52F68FF4
The module uses fs.watch to monitor a directory and invokes a callback when a specific file changes. It does not read, write, or exfiltrate file contents, and it stays within the directory of the watched file. No network, process spawning, environment access, or dynamic code execution is present.
Environment variable/context harvesting via locale
NPS-AD2D26AEAFBC
getNow resolves a value using the caller-provided locale property before falling back to a default. Although no explicit environment variables are read here, the pattern of passing user/caller context into a config resolver can be abused by other modules in the package to read application context. In this file alone it only reads a property from the argument, but it sits in a production server path and should be reviewed alongside getConfigNow.js/getDefaultNow.js to confirm it is not used for context leakage.
Indirect import-time execution
NPS-17A13C317A18
The module imports two sibling modules and immediately wires them into the default export. No top-level side effects are visible in this file, but the actual behavior depends on getConfigNow.js and getDefaultNow.js, which are not provided. If either sibling performs network, filesystem, or environment access at import time, this file will trigger it whenever the server entrypoint is loaded.
Environment Variable Access
NPS-79705A70775B
The code reads process.env._next_intl_trailing_slash to determine trailing slash behavior. This is a benign configuration flag used by Next.js internationalization, not credential harvesting or exfiltration.
Dynamic RegExp Construction
NPS-58A5A505B5B2
The function s(n) builds a RegExp from a path template by replacing route pattern syntax with capture groups. The input originates from application route definitions, not from external attacker-controlled sources, and is not eval-like code execution.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/cjs/development/plugin.cjs | medium | No outright malicious patterns (no exfiltration, credential harvesting, obfuscation, or reverse shells) were found; the package legitimately uses dynamic imports, native SWC plugins, file watchers, and filesystem writes as part of its message-extraction functionality, but these carry inherent risk if the package or its dependencies were compromised upstream. |
| dist/esm/development/extractor/ExtractionCompiler.js | medium | No malicious exfiltration, credential harvesting, obfuscation, or command execution was found; the main concerns are global process signal handler mutation and a possible event-listener cleanup bug, which are reliability rather than supply-chain attack issues. |
| dist/esm/development/extractor/extractor/MessageExtractor.js | medium | The extractor performs expected SWC-based message extraction with dynamic native plugin resolution but contains no clear malicious patterns such as exfiltration, credential harvesting, or shell execution. |
| dist/esm/development/extractor/format/index.js | medium | The code dynamically imports modules from user-controlled paths or package specifiers without sufficient validation, which could lead to arbitrary code execution if an attacker can influence the format configuration. |
| dist/esm/development/plugin/declaration/createMessagesDeclaration.js | medium | The code appears to be a legitimate part of the next-intl package, performing expected file system operations for generating TypeScript declarations, with no clear malicious intent, though it does access environment variables and manipulate files based on configurable paths. |
| dist/esm/production/extractor/ExtractionCompiler.js | medium | No direct malicious patterns are present in this file, but it installs global process handlers and delegates all meaningful behavior to unreviewed imported modules, requiring further inspection. |
| dist/esm/production/extractor/extractor/MessageExtractor.js | medium | No direct malicious patterns (exfiltration, credential theft, shell spawning, obfuscation) were detected, but the code relies on dynamic native plugin loading and build-time code transformation that carries inherent supply-chain risk. |
| dist/esm/production/extractor/format/index.js | medium | The extractor format module dynamically resolves and imports codec modules from user-influenced paths or package specifiers, creating a code-loading vector that could be abused if untrusted input reaches it, but no direct exfiltration, obfuscation, or process-spawning patterns are present. |
| dist/esm/production/plugin/declaration/createMessagesDeclaration.js | medium | This appears to be a legitimate next-intl build tool that generates TypeScript declaration files for message catalogs, with only minor concerns about file system writes to user-specified paths. |
| dist/esm/production/plugin/extractor/initExtractionCompiler.js | medium | The code appears to be a legitimate i18n extraction initializer with process-level side effects but no clear malicious patterns such as exfiltration or obfuscation. |
| dist/esm/production/server/react-server/getNow.js | medium | The file itself contains no overt malicious code, but its import-time dependencies and context-resolution pattern warrant warning-level review for potential data or locale/context leakage. |
| dist/cjs/development/BuiltInPoCodec-B6w-kmTx.cjs | safe | No malicious patterns detected; the code is a straightforward wrapper around @eloqnt/format-po with a migration guard. |
| dist/esm/development/config.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor/catalog/CatalogLocales.js | safe | No malicious patterns detected; code performs locale file management using safe file system operations within configured directories. |
| dist/esm/development/extractor/catalog/CatalogManager.js | safe | CatalogManager is a normal i18n catalog extraction/persistence manager with only scoped filesystem and format-plugin access, and no malicious patterns such as exfiltration, credential harvesting, code execution, or shell spawning. |
| dist/esm/development/extractor/catalog/CatalogPersister.js | safe | The code is a benign translation catalog file manager; it only performs expected file I/O within a configured directory and contains no obfuscation, network calls, process spawning, or credential harvesting. |
| dist/esm/development/extractor/catalog/SaveScheduler.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor/catalogLoader.js | safe | No malicious patterns detected; the code is a standard webpack/Next.js loader for parsing ICU message catalogs with caching and precompilation, using only local imports and no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/development/extractor/extractMessages.js | safe | No malicious patterns detected |
| dist/esm/development/extractor/extractionLoader.js | safe | No malicious patterns detected; the code is a standard Next.js webpack loader for message extraction with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/development/extractor/extractor/LRUCache.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor/format/ExtractorCodec.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor/format/codecs/BuiltInPoCodec.js | safe | No malicious patterns detected; the file only wraps a PO codec with a validation check for a deprecated catalog layout. |
| dist/esm/development/extractor/normalizeExtractorConfig.js | safe | Cleared by Jev triage; no further analysis needed |
Show 148 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/development/extractor/source/SourceFileFilter.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor/source/SourceFileScanner.js | safe | The code recursively scans directories for source files using safe filesystem operations and no malicious patterns were detected. |
| dist/esm/development/extractor/source/SourceFileWatcher.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/extractor/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/index.react-client.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/index.react-server.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/middleware.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/middleware/getAlternateLinksHeaderValue.js | safe | No malicious patterns detected; the code is a legitimate utility for generating alternate link headers in a localization/routing library. |
| dist/esm/development/middleware/middleware.js | safe | No malicious patterns detected; the code is a standard Next.js internationalization middleware with proper URL sanitization and no external data transmission or code execution. |
| dist/esm/development/middleware/resolveLocale.js | safe | This is a legitimate locale resolution middleware that uses standard libraries and performs no malicious operations such as data exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/esm/development/middleware/syncCookie.js | safe | No malicious patterns detected |
| dist/esm/development/middleware/utils.js | safe | No malicious patterns detected; the code is a routing/middleware utility focused on i18n path handling and includes defensive sanitization. |
| dist/esm/development/navigation.react-client.js | safe | No malicious patterns detected |
| dist/esm/development/navigation.react-server.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/navigation/react-client/createNavigation.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/navigation/react-client/useBasePathname.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/navigation/react-server/createNavigation.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/navigation/react-server/getServerLocale.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/navigation/shared/BaseLink.js | safe | No malicious patterns detected; the code is a standard React/Next.js link component with locale cookie synchronization logic. |
| dist/esm/development/navigation/shared/createSharedNavigationFns.js | safe | No malicious patterns detected; the file is a standard Next.js navigation helper with no exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| dist/esm/development/navigation/shared/syncLocaleCookie.js | safe | No malicious patterns detected; the code only syncs a locale cookie using document.cookie with expected cookie attributes. |
| dist/esm/development/navigation/shared/utils.js | safe | No malicious patterns detected; the code is a URL/pathname utility for next-intl with no network, filesystem, process, or dynamic execution abuse. |
| dist/esm/development/plugin.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/plugin/config.js | safe | No malicious patterns detected |
| dist/esm/development/plugin/createNextIntlPlugin.js | safe | No malicious patterns detected; the code is a legitimate Next.js plugin that configures internationalization extraction and message declaration, with no network, credential, or process-spawning activity. |
| dist/esm/development/plugin/extractor/initExtractionCompiler.js | safe | No malicious patterns detected; the code is a legitimate Next.js internationalization extraction compiler with standard lifecycle cleanup handlers. |
| dist/esm/development/plugin/getNextConfig.js | safe | No malicious patterns detected; the code is a legitimate Next.js plugin for next-intl that configures aliases and loaders for message extraction and formatting. |
| dist/esm/development/plugin/nextFlags.js | safe | No malicious patterns detected; the file only compares Next.js versions using createRequire to read the local next/package.json. |
| dist/esm/development/plugin/utils.js | safe | No malicious patterns detected; the code only provides formatting, error/warning helpers, and a one-time execution guard using an environment variable. |
| dist/esm/development/plugin/watchFile.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-client/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/NextIntlClientProviderServer.js | safe | No malicious patterns detected |
| dist/esm/development/react-server/useConfig.js | safe | No malicious patterns detected |
| dist/esm/development/react-server/useExtracted.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/useFormatter.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/useLocale.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/useMessages.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/useNow.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/useTimeZone.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/react-server/useTranslations.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/routing.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/routing/config.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/routing/defineRouting.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server.react-client.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server.react-server.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-client/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/RequestLocale.js | safe | No malicious patterns detected; the code is a benign locale retrieval utility using Next.js headers and React caching. |
| dist/esm/development/server/react-server/RequestLocaleCache.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/createRequestConfig.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getConfig.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getConfigNow.js | safe | No malicious patterns detected; the module simply reads and caches a 'now' config value. |
| dist/esm/development/server/react-server/getDefaultNow.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getExtracted.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getFormats.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getFormatter.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getLocale.js | safe | No malicious patterns detected |
| dist/esm/development/server/react-server/getMessages.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getNow.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getRequestConfig.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getServerExtractor.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getServerFormatter.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getServerTranslator.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/getTimeZone.js | safe | No malicious patterns detected |
| dist/esm/development/server/react-server/getTranslations.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/server/react-server/validateLocale.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/shared/NextIntlClientProvider.js | safe | No malicious patterns detected; the file is a simple React client provider wrapper with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/development/shared/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/development/shared/use.js | safe | No malicious patterns detected; the code uses a non-statically-analyzable property access to access React's use hook, which is a known workaround for Next.js/React version compatibility, not a security threat. |
| dist/esm/development/shared/utils.js | safe | No malicious patterns detected; the code contains only URL/path manipulation utilities for next-intl localization. |
| dist/esm/production/config.js | safe | No malicious patterns detected |
| dist/esm/production/extractor.js | safe | This file only performs static re-exports of two internal modules and contains no malicious patterns, network activity, filesystem access, or dynamic execution. |
| dist/esm/production/extractor/catalog/CatalogLocales.js | safe | The file implements locale message file watching and directory reading using standard Node.js fs/path APIs without any malicious patterns, external network calls, process execution, or credential harvesting. |
| dist/esm/production/extractor/catalog/CatalogManager.js | safe | No malicious patterns detected; the code is a legitimate catalog management module for a localization extraction tool and does not perform any network exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/esm/production/extractor/catalog/CatalogPersister.js | safe | No malicious patterns detected; the code is a benign catalog file persister that reads/writes translation files using standard Node.js fs/promises and path modules. |
| dist/esm/production/extractor/catalog/SaveScheduler.js | safe | No malicious patterns detected |
| dist/esm/production/extractor/catalogLoader.js | safe | The code is a webpack loader for next-intl that loads and compiles message catalog files; it uses standard Node.js/path and icu-minify compile APIs, performs predictable JSON serialization, and contains no exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns. |
| dist/esm/production/extractor/extractMessages.js | safe | No malicious patterns detected |
| dist/esm/production/extractor/extractionLoader.js | safe | No malicious patterns detected; the code is a standard webpack loader that conditionally sets development mode based on NODE_ENV and delegates extraction to a local MessageExtractor class. |
| dist/esm/production/extractor/extractor/LRUCache.js | safe | No malicious patterns detected |
| dist/esm/production/extractor/format/ExtractorCodec.js | safe | No malicious patterns detected |
| dist/esm/production/extractor/format/codecs/BuiltInPoCodec.js | safe | No malicious patterns detected; the code is a benign PO format codec with a migration error check. |
| dist/esm/production/extractor/normalizeExtractorConfig.js | safe | No malicious patterns detected; the code only validates and normalizes configuration objects with no network, filesystem, or execution risks. |
| dist/esm/production/extractor/source/SourceFileFilter.js | safe | No malicious patterns detected; the code only performs path-based source file filtering using standard path operations. |
| dist/esm/production/extractor/source/SourceFileScanner.js | safe | No malicious patterns detected; the code is a straightforward source file scanner using fs/promises and path with no network, process execution, credential access, or obfuscation. |
| dist/esm/production/extractor/source/SourceFileWatcher.js | safe | The code is a legitimate file watcher implementation using @parcel/watcher with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or shell commands. |
| dist/esm/production/extractor/utils.js | safe | No malicious patterns detected; the code contains only utility functions for path normalization, safe property setting, and message extraction warnings. |
| dist/esm/production/index.react-client.js | safe | No malicious patterns detected; this is a standard re-export barrel file for the next-intl library. |
| dist/esm/production/index.react-server.js | safe | No malicious patterns detected |
| dist/esm/production/middleware.js | safe | This file is a simple ESM re-export that contains no malicious patterns or suspicious behavior. |
| dist/esm/production/middleware/getAlternateLinksHeaderValue.js | safe | No malicious patterns detected; the code is a minified but legitimate middleware utility for generating alternate language link HTTP headers. |
| dist/esm/production/middleware/middleware.js | safe | No malicious patterns detected; the code is a legitimate Next.js middleware for internationalized routing with no data exfiltration, code execution, or other suspicious behavior. |
| dist/esm/production/middleware/resolveLocale.js | safe | No malicious patterns detected; the code appears to be a benign locale resolution middleware using standard libraries. |
| dist/esm/production/middleware/syncCookie.js | safe | The code is a minified locale cookie synchronization middleware with no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or network/file/process manipulation. |
| dist/esm/production/middleware/utils.js | safe | No malicious patterns detected in the provided utility functions; the code only performs pathname, locale, and routing-related string manipulations. |
| dist/esm/production/navigation.react-client.js | safe | The file is a simple ES module re-export with no malicious patterns, dynamic code execution, or suspicious behavior. |
| dist/esm/production/navigation.react-server.js | safe | No malicious patterns detected |
| dist/esm/production/navigation/react-client/createNavigation.js | safe | No malicious patterns detected |
| dist/esm/production/navigation/react-client/useBasePathname.js | safe | The code is a standard Next.js client hook for handling locale-prefixed pathnames and contains no malicious patterns. |
| dist/esm/production/navigation/react-server/createNavigation.js | safe | No malicious patterns detected; the code only creates a server-side navigation object and throws informative errors for unsupported hooks. |
| dist/esm/production/navigation/react-server/getServerLocale.js | safe | No malicious patterns detected |
| dist/esm/production/navigation/shared/BaseLink.js | safe | No malicious patterns detected |
| dist/esm/production/navigation/shared/createSharedNavigationFns.js | safe | No malicious patterns detected; the code is a minified Next.js navigation utility with local routing and redirect logic only. |
| dist/esm/production/navigation/shared/syncLocaleCookie.js | safe | The code is a benign cookie sync utility; it only writes a cookie using provided arguments and does not exhibit any malicious patterns. |
| dist/esm/production/navigation/shared/utils.js | safe | This is a legitimate utility module for Next.js internationalization (next-intl) that handles path localization, URL parameter serialization, and route matching without any malicious patterns. |
| dist/esm/production/plugin.js | safe | No malicious patterns detected; the file is a simple ESM re-export of a plugin module. |
| dist/esm/production/plugin/config.js | safe | No malicious patterns detected; the file only reads NODE_ENV and process.argv to export build-environment flags. |
| dist/esm/production/plugin/createNextIntlPlugin.js | safe | No malicious patterns detected; the code is a legitimate next-intl plugin that processes configuration and extraction options without exfiltration, obfuscation, or suspicious system access. |
| dist/esm/production/plugin/getNextConfig.js | safe | No malicious patterns detected; the code performs standard Next.js configuration manipulation for the next-intl library without any data exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/esm/production/plugin/nextFlags.js | safe | No malicious patterns detected |
| dist/esm/production/plugin/utils.js | safe | No malicious patterns detected; the code is a simple utility module for logging and one-time execution without any exfiltration, obfuscation, or system-level access. |
| dist/esm/production/plugin/watchFile.js | safe | No malicious patterns detected; the code only watches a file's directory for changes and triggers a provided callback. |
| dist/esm/production/react-client/index.js | safe | No malicious patterns detected |
| dist/esm/production/react-server/NextIntlClientProviderServer.js | safe | No malicious patterns detected |
| dist/esm/production/react-server/useConfig.js | safe | No malicious patterns detected; the code is a normal React server-hook wrapper from next-intl that only calls internal config/use utilities and provides a helpful error message. |
| dist/esm/production/react-server/useExtracted.js | safe | No malicious patterns detected |
| dist/esm/production/react-server/useFormatter.js | safe | No malicious patterns detected |
| dist/esm/production/react-server/useLocale.js | safe | No malicious patterns detected |
| dist/esm/production/react-server/useMessages.js | safe | No malicious patterns detected |
| dist/esm/production/react-server/useNow.js | safe | No malicious patterns detected; the code is a simple React Server Component hook that logs a console warning and reads a config value. |
| dist/esm/production/react-server/useTimeZone.js | safe | No malicious patterns detected; the file is a minimal React hook that reads timezone from a config module. |
| dist/esm/production/react-server/useTranslations.js | safe | The minified JavaScript file imports two internal modules and defines a simple translation hook; no malicious patterns such as exfiltration, credential harvesting, obfuscation, dynamic code execution, or network activity were detected. |
| dist/esm/production/routing.js | safe | No malicious patterns detected |
| dist/esm/production/routing/config.js | safe | No malicious patterns detected; the code is a standard routing configuration normalizer with no network, filesystem, process, or obfuscated behavior. |
| dist/esm/production/routing/defineRouting.js | safe | No malicious patterns detected |
| dist/esm/production/server.react-client.js | safe | This file only re-exports functions from a local module, with no malicious or suspicious code patterns. |
| dist/esm/production/server.react-server.js | safe | This file only contains standard re-exports of internal server-side utility modules (likely from the next-intl library) with no malicious patterns such as exfiltration, obfuscation, dynamic execution, or process spawning. |
| dist/esm/production/server/react-client/index.js | safe | The code only defines stub functions that throw errors when server-only APIs are used in Client Components, with no malicious patterns detected. |
| dist/esm/production/server/react-server/RequestLocale.js | safe | No malicious patterns detected; the code is a legitimate utility for retrieving request locale in Next.js server components. |
| dist/esm/production/server/react-server/RequestLocaleCache.js | safe | No malicious patterns detected; the code simply caches and retrieves a request locale value using React's cache function. |
| dist/esm/production/server/react-server/createRequestConfig.js | safe | The file contains only a simple re-export of the next-intl config module with no malicious patterns. |
| dist/esm/production/server/react-server/getConfig.js | safe | No malicious patterns detected; the code is a standard next-intl React server configuration loader using React cache and use-intl core utilities with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/production/server/react-server/getConfigNow.js | safe | No malicious patterns detected; the code simply caches and returns a 'now' value from a local config module. |
| dist/esm/production/server/react-server/getDefaultNow.js | safe | No malicious patterns detected |
| dist/esm/production/server/react-server/getExtracted.js | safe | No malicious patterns detected |
| dist/esm/production/server/react-server/getFormats.js | safe | The code is a simple React cache wrapper that retrieves format configuration; no malicious patterns detected. |
| dist/esm/production/server/react-server/getFormatter.js | safe | No malicious patterns detected; the module only uses React cache, a config loader, and a formatter, with no external network, filesystem, process, or dynamic code execution. |
| dist/esm/production/server/react-server/getLocale.js | safe | No malicious patterns detected; the code only wraps a cached async locale lookup via a local config module. |
| dist/esm/production/server/react-server/getMessages.js | safe | This is a straightforward 5-line utility from next-intl that caches message retrieval via React's cache API; no obfuscation, network calls, credential access, process spawning, or dynamic code execution is present. |
| dist/esm/production/server/react-server/getRequestConfig.js | safe | No malicious patterns detected |
| dist/esm/production/server/react-server/getServerExtractor.js | safe | No malicious patterns detected; the file is a small React cache wrapper that throws a descriptive error in production when useExtracted is called without compilation. |
| dist/esm/production/server/react-server/getServerFormatter.js | safe | No malicious patterns detected |
| dist/esm/production/server/react-server/getServerTranslator.js | safe | No malicious patterns detected; the code is a minimal React server-side translator wrapper using React cache and use-intl. |
| dist/esm/production/server/react-server/getTimeZone.js | safe | No malicious patterns detected |
| dist/esm/production/server/react-server/getTranslations.js | safe | No malicious patterns detected |
| dist/esm/production/shared/NextIntlClientProvider.js | safe | No malicious patterns detected |
| dist/esm/production/shared/constants.js | safe | The file only exports a constant string for a locale header name, with no malicious patterns detected. |
| dist/esm/production/shared/use.js | safe | No malicious patterns detected |
| dist/esm/production/shared/utils.js | safe | No malicious patterns detected; the file contains benign Next.js internationalization routing utilities with no exfiltration, code execution, or network activity. |
Frequently asked questions
Is next-intl safe to use?
No confirmed malware was found in next-intl@4.14.9, but the review flagged 9 medium, 29 low severity findings for risky patterns worth checking before you rely on it.
Does next-intl contain malware?
No malware was identified in next-intl@4.14.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was next-intl checked?
Togoder Security downloaded the published npm package and had an AI model read its 173 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan next-intl together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in next-intl@4.14.9, cost nothing.