Summary
Togoder Security scanned the npm package orval@8.39.0 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
dynamic import
NPS-4C67384F511E
The generate function uses a dynamic import() to load a local module ('./generate-Tb6cDX2C.mjs') at call time. While the path is static and relative, dynamic imports can be used to obfuscate code and delay execution, making static analysis harder. This is not inherently malicious but warrants review of the imported module.
File system manipulation
NPS-F43104C45667
The code reads and writes barrel files (index files with re-exports) using fs and writeGeneratedFile from @orval/core. Operations are limited to the file paths provided as arguments (e.g., indexFile, filePath) and their sibling directories. No sensitive paths like ~/.ssh, ~/.npmrc, or environment variables are accessed.
Path resolution from specifiers
NPS-1B8BA0A356CE
reExportSpecifierExists resolves relative specifiers against the directory of the index file and checks candidate files. This is standard module resolution logic and does not traverse outside the project structure based on untrusted input.
re-export from external dependency
NPS-9FD756A69CDD
The file re-exports everything from '@orval/core'. This could expose additional functions from the dependency, but does not itself introduce malicious behavior. Still, it increases the attack surface if the dependency is compromised.
Network request
NPS-E9B96881E985
The code performs HEAD/GET requests to user-provided input URLs (with 10s timeout) to validate targets. This is expected behavior for a code generator that can fetch remote OpenAPI specs; no exfiltration of local data is present.
Dynamic import
NPS-9D23B8D15154
Uses dynamicImport for local package.json files and a static import('@orval/mock'). No computed/external attacker-controlled module loading is observed.
File system access
NPS-725B7FA3476C
Reads package.json, tsconfig.json, pnpm-workspace.yaml, .yarnrc.yml from the workspace and walks to filesystem root. This is normal configuration discovery, not credential harvesting.
Module resolution
NPS-CE17C788C8D8
Uses createRequire to resolve package specifiers from the workspace, which is expected for resolving mutators/schemas imports.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.mjs | medium | The file uses dynamic import and re-exports from a dependency; while no clear malicious patterns are present, the delayed module loading deserves closer inspection of the imported file. |
| dist/barrel-D9EU9nTw.mjs | safe | The code performs legitimate barrel file reconciliation for generated re-exports, with no exfiltration, credential harvesting, obfuscation, or malicious execution patterns. |
| dist/bin/orval.mjs | safe | No malicious patterns detected |
| dist/generate-Tb6cDX2C.mjs | safe | No malicious patterns detected; the code is a standard Orval API generation module that uses expected library imports and performs no suspicious network, filesystem, credential, or process operations. |
| dist/options-BazNQK7L.mjs | safe | No malicious patterns detected; the code is a legitimate orval configuration/options normalization module with expected network, filesystem, and dynamic-import usage. |
| dist/write-zod-specs-BWwpK_l2.mjs | safe | The file is a legitimate orval code-generation module that transforms OpenAPI schemas into Zod validation code, with no exfiltration, process spawning, dynamic code execution, credential harvesting, or other malicious patterns. |
Frequently asked questions
Is orval safe to use?
No confirmed malware was found in orval@8.39.0, but the review flagged 1 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does orval contain malware?
No malware was identified in orval@8.39.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was orval checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan orval together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in orval@8.39.0, cost nothing.