Togoder security

npm package security report

npm-audit-report@7.0.0 security report

Critical: dangerous or likely malicious code found.

Critical risk Version 7.0.0 Files reviewed 7 Size 6.7 KB Scanned

Summary

Togoder Security scanned the npm package npm-audit-report@7.0.0 on Oct 6, 2026. An AI review of 7 source files produced 1 high severity finding. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

0
critical
1
high
0
medium
0
low

Findings 1

high

Logic error / incorrect severity comparison

NPS-16CDF8ADC9C3

The severities Map is built by calling s.reverse() on each string. reverse() mutates and returns the reversed string (e.g., 'critical' -> 'lacitirc'), so the Map keys become reversed severity names. As a result, severities.get(sev) and severities.get(level) will return undefined for normal inputs like 'high' or 'critical', and the comparison will always evaluate to false, causing the module to always return 0 instead of 1 for vulnerable packages. This silently disables vulnerability-based exit code failures, which is a security-relevant defect.

lib/exit-code.js:2

Files reviewed

FileVerdictWhat the reviewer saw
lib/exit-code.js critical No malicious patterns detected, but the code contains a critical logic bug that silently disables vulnerability severity checks by reversing map keys.
lib/colors.js safe Cleared by Jev triage; no further analysis needed
lib/index.js safe No malicious patterns detected; the code is a straightforward audit report formatter with no network, filesystem, or process-execution behavior.
lib/reporters/detail.js safe Cleared by Jev triage; no further analysis needed
lib/reporters/install.js safe Cleared by Jev triage; no further analysis needed
lib/reporters/json.js safe Cleared by Jev triage; no further analysis needed
lib/reporters/quiet.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is npm-audit-report safe to use?

npm-audit-report@7.0.0 has 1 high severity finding, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.

Does npm-audit-report contain malware?

The latest scan of npm-audit-report (7.0.0) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.

How was npm-audit-report checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan npm-audit-report together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in npm-audit-report@7.0.0, cost nothing.

Related security reports