Summary
Togoder Security scanned the npm package node-gyp-build@4.8.4 on Oct 4, 2026. An AI review of 5 source files produced 1 high, 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
Command execution with user-controlled input
NPS-6B7E9E54F95A
The exec function spawns shell commands using process.argv[2] and process.argv[3] without any validation. An attacker who can control command-line arguments passed to this script could execute arbitrary shell commands.
Dynamic child process spawning
NPS-A431F751FF12
The script uses child_process.spawn and child_process.exec to run external commands (node-gyp, node-gyp-build-test, and user-supplied commands). While this is common for build tools, it introduces risk if inputs are not sanitized.
Dynamic code execution via require()
NPS-C8417CF7B944
The script dynamically requires a module based on the 'prebuild.test' field from package.json, which is read from the current working directory. If an attacker can influence the package.json or the value of prebuild.test, they could execute arbitrary code by pointing to a malicious file. However, this is likely intended behavior for a test runner.
Dynamic require of relative path
NPS-5470F5D605D6
The script requires a module relative to the current working directory, which could execute arbitrary code if the current directory is untrusted. However, this is typical for build/test scripts.
Environment variable usage for build flags
NPS-B4ADC2D30187
Reads npm_config_argv and npm_config_build_from_source environment variables to conditionally execute build commands. No exfiltration or credential harvesting, but behavior can be influenced by environment variables.
Environment variable check to bypass execution
NPS-0D39E4AF10AF
The script checks if an environment variable based on the package name (uppercased, hyphens replaced with underscores) is set, and if so, exits early. This could be used to skip tests or avoid detection, but it's not inherently malicious and may be a legitimate feature.
dynamic module loading
NPS-58443C5C70C6
The code dynamically selects between a native addon loader and a runtime JavaScript fallback based on the presence of a custom addon method on the require function. While this is a common pattern for packages like node-gyp-build, it constitutes dynamic module resolution that could be abused if the runtime environment or dependencies are compromised. No direct exfiltration or malicious behavior is present in this file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bin.js | medium | This is a legitimate build helper script for node-gyp that executes shell commands, but it lacks input validation on command-line arguments, posing a potential command injection risk if arguments are attacker-controlled. |
| build-test.js | medium | The script dynamically loads code based on package.json configuration and environment variables, which could be abused if the package or its configuration is compromised, but it appears to be a standard test runner with no overtly malicious patterns. |
| index.js | medium | The file is a benign native module loader with dynamic resolution but no overt malicious patterns; risk is low but noted due to dynamic loading behavior. |
| node-gyp-build.js | safe | No malicious patterns detected; the code is a legitimate native module loader used by packages like node-gyp-build. |
| optional.js | safe | The script simply exits successfully to skip optional native dependency compilation and contains no malicious patterns. |
Frequently asked questions
Is node-gyp-build safe to use?
No confirmed malware was found in node-gyp-build@4.8.4, but the review flagged 1 high, 3 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does node-gyp-build contain malware?
No malware was identified in node-gyp-build@4.8.4 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was node-gyp-build checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan node-gyp-build together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-gyp-build@4.8.4, cost nothing.