Summary
Togoder Security scanned the npm package npm-audit-report@7.0.0 on Oct 6, 2026. An AI review of 7 source files produced 1 high severity finding. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.
Findings 1
Logic error / incorrect severity comparison
NPS-16CDF8ADC9C3
The severities Map is built by calling s.reverse() on each string. reverse() mutates and returns the reversed string (e.g., 'critical' -> 'lacitirc'), so the Map keys become reversed severity names. As a result, severities.get(sev) and severities.get(level) will return undefined for normal inputs like 'high' or 'critical', and the comparison will always evaluate to false, causing the module to always return 0 instead of 1 for vulnerable packages. This silently disables vulnerability-based exit code failures, which is a security-relevant defect.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/exit-code.js | critical | No malicious patterns detected, but the code contains a critical logic bug that silently disables vulnerability severity checks by reversing map keys. |
| lib/colors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | No malicious patterns detected; the code is a straightforward audit report formatter with no network, filesystem, or process-execution behavior. |
| lib/reporters/detail.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/reporters/install.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/reporters/json.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/reporters/quiet.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of npm-audit-report
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 7.0.0 | Critical risk | 7 | Oct 6, 2026 |
Frequently asked questions
Is npm-audit-report safe to use?
npm-audit-report@7.0.0 has 1 high severity finding, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.
Does npm-audit-report contain malware?
The latest scan of npm-audit-report (7.0.0) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.
How was npm-audit-report checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan npm-audit-report together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in npm-audit-report@7.0.0, cost nothing.