Summary
Togoder Security scanned the npm package node-mock-http@1.0.4 on Oct 4, 2026. An AI review of 10 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
Informational
NPS-4264FA51A477
This is a bundled, minified/obfuscated polyfill of the standard Node.js 'buffer' module (nodeless/browser build). It contains standard buffer implementation code, base64/hex/utf8 conversions, and IEEE754 float read/write helpers. No network calls, environment/credential access, file system manipulation, process spawning, eval/Function usage, or other malicious patterns are present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/_polyfill/buffer/node.cjs | safe | No malicious patterns detected |
| dist/_polyfill/buffer/node.mjs | safe | No malicious patterns detected |
| dist/_polyfill/buffer/nodeless.cjs | safe | The file is a legitimate 'buffer' polyfill with no detectable malicious patterns; risk is limited to the usual obfuscation from bundling/minification. |
| dist/_polyfill/buffer/nodeless.mjs | safe | No malicious patterns detected; the code is a legitimate Buffer polyfill with no data exfiltration, obfuscation, or dynamic code execution. |
| dist/_polyfill/events/node.cjs | safe | No malicious patterns detected |
| dist/_polyfill/events/node.mjs | safe | This file simply re-exports the built-in Node.js EventEmitter from node:events with no obfuscation, side effects, or malicious patterns. |
| dist/_polyfill/events/nodeless.cjs | safe | This is a legitimate bundled polyfill implementation of Node.js's events module with no malicious patterns detected. |
| dist/_polyfill/events/nodeless.mjs | safe | This is a legitimate nodeless EventEmitter polyfill with no malicious patterns detected. |
| dist/index.cjs | safe | No malicious patterns detected; the code is a polyfill/mock implementation of Node.js HTTP stream modules with no network, filesystem, process, or dynamic code execution behaviors. |
| dist/index.mjs | safe | No malicious patterns detected; the code is a Node.js HTTP polyfill with only stub implementations and no data exfiltration, credential harvesting, obfuscation, or process execution. |
Affected version ranges
None of the 2 scanned versions of node-mock-http are flagged high or critical. The latest scanned version, 1.0.5, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of node-mock-http
Frequently asked questions
Is node-mock-http safe to use?
Our AI source review of node-mock-http@1.0.4 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does node-mock-http contain malware?
No malware was identified in node-mock-http@1.0.4 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was node-mock-http checked?
Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan node-mock-http together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-mock-http@1.0.4, cost nothing.