Summary
Togoder Security scanned the npm package openid-client@5.7.1 on Oct 6, 2026. An AI review of 29 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Potential SSRF via JWKS URI
NPS-FCADD61B6B2C
No validation or restriction on the jwks_uri scheme or host. An attacker who can control issuer configuration could potentially direct requests to internal services.
Network request with dynamic URL
NPS-D3B67D0F034A
The code performs an HTTP GET request to this.jwks_uri, which is a configurable issuer URL. This is normal behavior for JWKS fetching, but the URL is not validated against a whitelist, potentially allowing SSRF if attacker controls issuer configuration.
Network requests (benign)
NPS-BD4BCC557AC1
The code makes outbound HTTPS requests to fetch OpenID Connect discovery documents and WebFinger metadata. These are standard, expected behaviors for an OpenID Connect client library and are not data exfiltration. The endpoints are derived from the user-supplied issuer URL and fixed Microsoft AAD discovery URLs.
Dynamic property definitions (benign)
NPS-0DA58B032C40
Object.defineProperty is used to expose metadata keys as getters. This is used to build a public API object from trusted/validated response data, not for dynamic code execution. No eval, new Function, or similar constructs are present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/helpers/issuer.js | medium | No malicious patterns detected; the code is a legitimate JWKS keystore manager with standard network fetching, LRU caching, and in-flight request deduplication, though it lacks SSRF protections on the configurable jwks_uri. |
| lib/client.js | safe | No malicious patterns detected; the code is a legitimate OpenID Connect client library. |
| lib/device_flow_handle.js | safe | No malicious patterns detected |
| lib/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/assert.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/base64url.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/client.js | safe | The code is a legitimate OpenID client authentication helper that signs JWTs and constructs auth requests without any malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or backdoor installation. |
| lib/helpers/consts.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/decode_jwt.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/deep_clone.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/defaults.js | safe | No malicious patterns detected; the code is a standard deep object merging utility with prototype pollution protection. |
| lib/helpers/generators.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/is_key_object.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/is_plain_object.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/keystore.js | safe | No malicious patterns detected |
| lib/helpers/merge.js | safe | No malicious patterns detected; the code is a standard deep merge utility with explicit __proto__ and constructor guards to prevent prototype pollution. |
| lib/helpers/pick.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/process_response.js | safe | The code performs normal HTTP response processing without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| lib/helpers/request.js | safe | No malicious patterns detected |
| lib/helpers/unix_timestamp.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/weak_cache.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/helpers/webfinger_normalize.js | safe | No malicious patterns detected; the code is a pure string normalization helper for WebFinger URIs with no network, filesystem, process, or dynamic code execution behavior. |
| lib/helpers/www_authenticate_parser.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
Show 4 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/issuer.js | safe | The module implements standard OpenID Connect issuer discovery and metadata handling; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or process spawning were detected. |
| lib/issuer_registry.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/passport_strategy.js | safe | No malicious patterns detected |
| lib/token_set.js | safe | No malicious patterns detected; the code is a legitimate JWT TokenSet utility handling expiration and claims parsing. |
Scanned versions of openid-client
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 5.7.1 | Needs review | 29 | Oct 6, 2026 |
Frequently asked questions
Is openid-client safe to use?
No confirmed malware was found in openid-client@5.7.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does openid-client contain malware?
No malware was identified in openid-client@5.7.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was openid-client checked?
Togoder Security downloaded the published npm package and had an AI model read its 29 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan openid-client together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in openid-client@5.7.1, cost nothing.