Togoder security

npm package security report

node-addon-api npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 7.1.1 Files reviewed 5 Size 22.1 KB Scanned

Summary

Togoder Security scanned the npm package node-addon-api@7.1.1 on Oct 6, 2026. An AI review of 5 source files produced 4 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
6
low

Findings 10

medium

Unvalidated User-Controlled Target Directory

NPS-66FE267154AF

The target directory is taken directly from process.argv without any path validation, canonicalization, or confinement. An attacker who can influence the arguments (e.g., via a wrapper script or CI configuration) could direct the tool to rewrite arbitrary files on the filesystem, achieving data destruction or tampering with build configurations.

tools/conversion.js:8
medium

Shell Command Injection via binding.gyp Rewrite

NPS-E59B405D0838

The script injects '<!(node -p "require('node-addon-api').include_dir")' expressions into binding.gyp files. These gyp directives execute shell commands at build time. While intended for legitimate include_dir resolution, this introduces build-time command execution into any target project that processes the rewritten binding.gyp, which is a potential supply-chain risk if the target project is later built in an untrusted context.

tools/conversion.js:26
medium

Unbounded Recursive File Rewrite

NPS-385B49F0E3D5

convertFile uses fs.writeFile without validation of the target path against the package scope or a safe root. Combined with listFiles skipping only 'node_modules', the tool will rewrite every matching source/config file in the given directory tree, including files in user projects, home directories, or system paths if the user passes such a path. This is a destructive file-system operation outside the package's own scope.

tools/conversion.js:297
medium

Filesystem Modification

NPS-79186E9905D9

The script recursively scans and modifies files (package.json, binding.gyp, .h, .cc, .cpp) in a user-specified directory. This is expected behavior for a migration tool (nan to node-addon-api), but it performs bulk in-place rewrites outside the package's own scope if pointed at arbitrary directories. A malicious or careless invocation could corrupt or alter unrelated projects.

tools/conversion.js:305
low

Process spawning

NPS-7619CE794D01

The script uses child_process.spawn() to execute external commands 'nm' (on Unix) and 'dumpbin' (on Windows) against discovered .node files. While this appears to be for legitimate N-API symbol inspection, spawning external processes is a notable security-relevant behavior that could be abused if the script's logic were altered or if the target files were attacker-controlled.

tools/check-napi.js:12
low

File system traversal

NPS-8B6E2CAF218E

The recurse() function recursively walks the file system starting from a directory supplied via process.argv (defaults to current directory). It reads directory contents and stats files outside the package's own scope. This is expected for a developer tool but represents file system access beyond the package directory.

tools/check-napi.js:76
low

Top-level execution on import

NPS-2A671E6FAA62

The script executes recurse() at the top level (line 110) based on process.argv. If this file were required as a module rather than run as a CLI script, it would still perform file system traversal and process spawning. However, the code is clearly intended as a CLI tool (tools/check-napi.js) and this behavior is expected.

tools/check-napi.js:110
low

Environment Variable Use

NPS-4C06A2D1A517

Reads process.env.FORMAT_START to control the git diff base reference. This is a benign configuration option but could be manipulated by an attacker with control over the environment to alter which files are checked.

tools/eslint-format.js:4
low

Process Spawning

NPS-9E218AE14A7F

Uses child_process.spawnSync to execute git and eslint binaries. While the paths are fixed and arguments are constructed from git output, this is a legitimate pattern for a linting tool but warrants attention as a process-spawning operation.

tools/eslint-format.js:23
low

Command Execution via External Binary

NPS-A29989F91C81

Spawns the local ESLint binary from node_modules with file paths derived from git diff output. The file paths are passed as separate array arguments (not through a shell), so command injection risk is mitigated, but the tool executes an external binary present in the package's node_modules.

tools/eslint-format.js:51

Files reviewed

FileVerdictWhat the reviewer saw
tools/check-napi.js medium The script is a legitimate developer utility for detecting N-API modules via nm/dumpbin; it spawns external processes and traverses the file system as intended, with no evidence of exfiltration, credential harvesting, obfuscation, or backdoor behavior.
tools/conversion.js medium The script is a legitimate nan-to-node-addon-api migration tool but performs unrestricted, unvalidated in-place recursive file rewrites and injects build-time shell-executing gyp directives, posing a moderate supply-chain/destructive-operation risk.
tools/eslint-format.js medium This is a legitimate ESLint formatting helper script that spawns git and eslint processes; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation were detected, though it does use child_process and environment variables in normal ways.
index.js safe Cleared by Jev triage; no further analysis needed
tools/clang-format.js safe No malicious patterns detected

Affected version ranges

None of the 2 scanned versions of node-addon-api are flagged high or critical. The latest scanned version, 8.9.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.0.28.9.0
VersionsVerdictCountRangeTop findings
8.3.1 – 8.9.0 Not scanned 2 >=8.3.1 <=8.9.0
7.1.1 Needs review 1 7.1.1 Filesystem Modification; Shell Command Injection via binding.gyp Rewrite
3.2.1 – 7.1.0 Not scanned 3 >=3.2.1 <=7.1.0
2.0.2 Needs review 1 2.0.2 File system manipulation outside package scope; Dynamic code execution via shell

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of node-addon-api

VersionVerdictFilesScanned
7.1.1 Needs review 5 Oct 6, 2026
2.0.2 Needs review 3 Oct 4, 2026

Frequently asked questions

Is node-addon-api safe to use?

No confirmed malware was found in node-addon-api@7.1.1, but the review flagged 4 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does node-addon-api contain malware?

No malware was identified in node-addon-api@7.1.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was node-addon-api checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan node-addon-api together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-addon-api@7.1.1, cost nothing.

Related security reports