# node-addon-api@2.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:35:41.000Z
- Files reviewed: 3
- Findings: 3 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/node-addon-api@2.0.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package node-addon-api@2.0.2 on Oct 4, 2026. An AI review of 3 source files produced 3 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution via shell

Finding ID: `NPS-C697878CA228`

File: `tools/conversion.js:33`

The regex replacements inject shell command substitutions into binding.gyp files using node -p and require(...) expressions. These gyp directives are executed by node-gyp at build time, meaning modified build files will run arbitrary Node.js code during the native addon build process. Although the injected commands reference the node-addon-api package, the pattern establishes a code-execution vector if the tool is manipulated or if an attacker can control input files.

### [medium] Spawning processes or shell commands

Finding ID: `NPS-DF8A96D42B84`

File: `tools/conversion.js:34`

The conversion logic writes <!(node -p ...)> instructs into binding.gyp. During subsequent native builds, node-gyp will spawn Node.js processes to evaluate these expressions. This is indirect process spawning triggered by the script's output.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-22A35A0B88DC`

File: `tools/conversion.js:389`

The script accepts a target directory as a command-line argument and recursively modifies all matching source and config files within that directory. While this is the intended purpose of the conversion tool, it blindly overwrites files without confirmation and does not restrict to the package's own directory, which could be abused if the argument is controlled by an attacker.

### [low] spawning processes

Finding ID: `NPS-C00CDED1BEE4`

File: `tools/check-napi.js:12`

The code uses child_process.spawn to execute external commands ('nm' on Unix, 'dumpbin' on Windows) on files found during recursion. While these are standard build/tooling commands, executing subprocesses on arbitrary .node files within a directory tree could be abused if a malicious file is named to exploit argument injection, though the arguments here are fixed and paths are passed as separate argv elements, mitigating shell injection.

### [low] potential command injection via file paths

Finding ID: `NPS-182321FB87C4`

File: `tools/check-napi.js:12`

The file path is passed as an argument to child_process.spawn without shell, so injection is not possible. However, if a file name contains special characters, it could still be misinterpreted by the underlying nm/dumpbin tools, though impact is limited to those tools.

### [low] file system manipulation outside package scope

Finding ID: `NPS-AF57E7D53EB8`

File: `tools/check-napi.js:76`

The recurse function starts from a directory provided via process.argv or the current directory, and recursively traverses and stats files. This can read arbitrary directories outside the package if a caller supplies a path, but it only reads directory entries and stats, not file contents, and only invokes external tools on *.node files. This is typical for a build/tooling script but could be considered minor scope creep.

### [low] Insecure file permissions / atomicity

Finding ID: `NPS-EC9DBF80FD90`

File: `tools/conversion.js:404`

Files are read and written asynchronously without locking. Concurrent invocation or interruptions could lead to partially written files, though this is a robustness concern rather than a direct security vulnerability.

## Files reviewed

- `tools/check-napi.js` (medium): The script is a legitimate build utility for detecting N-API modules by spawning nm/dumpbin on *.node files; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were found, though it does spawn external processes and recursively traverse directories.
- `tools/conversion.js` (medium): The script is an intentional migration tool for converting native addon projects from nan to node-addon-api; it performs mass file modification and injects code-execution directives into build files, which are expected for its function but represent potential misuse if the tool is run on untrusted directories.
- `index.js` (safe): No malicious patterns detected; the code only performs Node.js version detection and path resolution for build configuration.

## Version ranges

None of the 2 scanned versions of node-addon-api are flagged high or critical. The latest scanned version, 8.9.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.3.1 – 8.9.0 (`>=8.3.1 <=8.9.0`): not scanned
- 7.1.1 (`7.1.1`): medium (Filesystem Modification +3 more)
- 3.2.1 – 7.1.0 (`>=3.2.1 <=7.1.0`): not scanned
- 2.0.2 (`2.0.2`): medium (File system manipulation outside package scope +2 more)

## Scanned versions

- [7.1.1](https://security.togoder.click/npm/node-addon-api@7.1.1): medium, 2026-10-06T14:22:52.000Z
- [2.0.2](https://security.togoder.click/npm/node-addon-api@2.0.2): medium, 2026-10-04T16:35:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
