Togoder security

npm package security report

node-addon-api@2.0.2 security report

Risky patterns found that deserve a look.

Needs review Version 2.0.2 Files reviewed 3 Size 19.9 KB Scanned

Summary

Togoder Security scanned the npm package node-addon-api@2.0.2 on Oct 4, 2026. An AI review of 3 source files produced 3 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
4
low

Findings 7

medium

Dynamic code execution via shell

NPS-C697878CA228

The regex replacements inject shell command substitutions into binding.gyp files using node -p and require(...) expressions. These gyp directives are executed by node-gyp at build time, meaning modified build files will run arbitrary Node.js code during the native addon build process. Although the injected commands reference the node-addon-api package, the pattern establishes a code-execution vector if the tool is manipulated or if an attacker can control input files.

tools/conversion.js:33
medium

Spawning processes or shell commands

NPS-DF8A96D42B84

The conversion logic writes <!(node -p ...)> instructs into binding.gyp. During subsequent native builds, node-gyp will spawn Node.js processes to evaluate these expressions. This is indirect process spawning triggered by the script's output.

tools/conversion.js:34
medium

File system manipulation outside package scope

NPS-22A35A0B88DC

The script accepts a target directory as a command-line argument and recursively modifies all matching source and config files within that directory. While this is the intended purpose of the conversion tool, it blindly overwrites files without confirmation and does not restrict to the package's own directory, which could be abused if the argument is controlled by an attacker.

tools/conversion.js:389
low

spawning processes

NPS-C00CDED1BEE4

The code uses child_process.spawn to execute external commands ('nm' on Unix, 'dumpbin' on Windows) on files found during recursion. While these are standard build/tooling commands, executing subprocesses on arbitrary .node files within a directory tree could be abused if a malicious file is named to exploit argument injection, though the arguments here are fixed and paths are passed as separate argv elements, mitigating shell injection.

tools/check-napi.js:12
low

potential command injection via file paths

NPS-182321FB87C4

The file path is passed as an argument to child_process.spawn without shell, so injection is not possible. However, if a file name contains special characters, it could still be misinterpreted by the underlying nm/dumpbin tools, though impact is limited to those tools.

tools/check-napi.js:12
low

file system manipulation outside package scope

NPS-AF57E7D53EB8

The recurse function starts from a directory provided via process.argv or the current directory, and recursively traverses and stats files. This can read arbitrary directories outside the package if a caller supplies a path, but it only reads directory entries and stats, not file contents, and only invokes external tools on *.node files. This is typical for a build/tooling script but could be considered minor scope creep.

tools/check-napi.js:76
low

Insecure file permissions / atomicity

NPS-EC9DBF80FD90

Files are read and written asynchronously without locking. Concurrent invocation or interruptions could lead to partially written files, though this is a robustness concern rather than a direct security vulnerability.

tools/conversion.js:404

Files reviewed

FileVerdictWhat the reviewer saw
tools/check-napi.js medium The script is a legitimate build utility for detecting N-API modules by spawning nm/dumpbin on *.node files; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were found, though it does spawn external processes and recursively traverse directories.
tools/conversion.js medium The script is an intentional migration tool for converting native addon projects from nan to node-addon-api; it performs mass file modification and injects code-execution directives into build files, which are expected for its function but represent potential misuse if the tool is run on untrusted directories.
index.js safe No malicious patterns detected; the code only performs Node.js version detection and path resolution for build configuration.

Affected version ranges

None of the 2 scanned versions of node-addon-api are flagged high or critical. The latest scanned version, 8.9.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.0.28.9.0
VersionsVerdictCountRangeTop findings
8.3.1 – 8.9.0 Not scanned 2 >=8.3.1 <=8.9.0
7.1.1 Needs review 1 7.1.1 Filesystem Modification; Shell Command Injection via binding.gyp Rewrite
3.2.1 – 7.1.0 Not scanned 3 >=3.2.1 <=7.1.0
2.0.2 Needs review 1 2.0.2 File system manipulation outside package scope; Dynamic code execution via shell

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of node-addon-api

VersionVerdictFilesScanned
7.1.1 Needs review 5 Oct 6, 2026
2.0.2 Needs review 3 Oct 4, 2026

Frequently asked questions

Is node-addon-api safe to use?

No confirmed malware was found in node-addon-api@2.0.2, but the review flagged 3 medium, 4 low severity findings for risky patterns worth checking before you rely on it.

Does node-addon-api contain malware?

No malware was identified in node-addon-api@2.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was node-addon-api checked?

Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan node-addon-api together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-addon-api@2.0.2, cost nothing.

Related security reports