Togoder security

npm package security report

orval@8.39.0 security report

Risky patterns found that deserve a look.

Needs review Version 8.39.0 Files reviewed 6 Size 207.7 KB Scanned

Summary

Togoder Security scanned the npm package orval@8.39.0 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
7
low

Findings 8

medium

dynamic import

NPS-4C67384F511E

The generate function uses a dynamic import() to load a local module ('./generate-Tb6cDX2C.mjs') at call time. While the path is static and relative, dynamic imports can be used to obfuscate code and delay execution, making static analysis harder. This is not inherently malicious but warrants review of the imported module.

dist/index.mjs:4
low

File system manipulation

NPS-F43104C45667

The code reads and writes barrel files (index files with re-exports) using fs and writeGeneratedFile from @orval/core. Operations are limited to the file paths provided as arguments (e.g., indexFile, filePath) and their sibling directories. No sensitive paths like ~/.ssh, ~/.npmrc, or environment variables are accessed.

dist/barrel-D9EU9nTw.mjs
low

Path resolution from specifiers

NPS-1B8BA0A356CE

reExportSpecifierExists resolves relative specifiers against the directory of the index file and checks candidate files. This is standard module resolution logic and does not traverse outside the project structure based on untrusted input.

dist/barrel-D9EU9nTw.mjs:14
low

re-export from external dependency

NPS-9FD756A69CDD

The file re-exports everything from '@orval/core'. This could expose additional functions from the dependency, but does not itself introduce malicious behavior. Still, it increases the attack surface if the dependency is compromised.

dist/index.mjs:2
low

Network request

NPS-E9B96881E985

The code performs HEAD/GET requests to user-provided input URLs (with 10s timeout) to validate targets. This is expected behavior for a code generator that can fetch remote OpenAPI specs; no exfiltration of local data is present.

dist/options-BazNQK7L.mjs
low

Dynamic import

NPS-9D23B8D15154

Uses dynamicImport for local package.json files and a static import('@orval/mock'). No computed/external attacker-controlled module loading is observed.

dist/options-BazNQK7L.mjs
low

File system access

NPS-725B7FA3476C

Reads package.json, tsconfig.json, pnpm-workspace.yaml, .yarnrc.yml from the workspace and walks to filesystem root. This is normal configuration discovery, not credential harvesting.

dist/options-BazNQK7L.mjs
low

Module resolution

NPS-CE17C788C8D8

Uses createRequire to resolve package specifiers from the workspace, which is expected for resolving mutators/schemas imports.

dist/options-BazNQK7L.mjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.mjs medium The file uses dynamic import and re-exports from a dependency; while no clear malicious patterns are present, the delayed module loading deserves closer inspection of the imported file.
dist/barrel-D9EU9nTw.mjs safe The code performs legitimate barrel file reconciliation for generated re-exports, with no exfiltration, credential harvesting, obfuscation, or malicious execution patterns.
dist/bin/orval.mjs safe No malicious patterns detected
dist/generate-Tb6cDX2C.mjs safe No malicious patterns detected; the code is a standard Orval API generation module that uses expected library imports and performs no suspicious network, filesystem, credential, or process operations.
dist/options-BazNQK7L.mjs safe No malicious patterns detected; the code is a legitimate orval configuration/options normalization module with expected network, filesystem, and dynamic-import usage.
dist/write-zod-specs-BWwpK_l2.mjs safe The file is a legitimate orval code-generation module that transforms OpenAPI schemas into Zod validation code, with no exfiltration, process spawning, dynamic code execution, credential harvesting, or other malicious patterns.

Frequently asked questions

Is orval safe to use?

No confirmed malware was found in orval@8.39.0, but the review flagged 1 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does orval contain malware?

No malware was identified in orval@8.39.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was orval checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan orval together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in orval@8.39.0, cost nothing.

Related security reports