Summary
Togoder Security scanned the npm package pathe@2.0.3 on Oct 6, 2026. An AI review of 6 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
Minified/Bundled Code
NPS-013CB71CD415
The file contains minified/bundled code (likely from a library like zeptomatch and pathe). Minification is not malicious per se, but it reduces readability. No suspicious behavior such as exfiltration, credential harvesting, or dynamic code execution was found.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs | safe | No malicious patterns detected; the code is a thin re-export wrapper for the pathe path utility library with platform delimiter handling. |
| dist/index.mjs | safe | The code is a thin wrapper around the pathe path utility library, using standard Proxy objects to expose posix/win32 variants; no malicious patterns such as network calls, credential harvesting, process spawning, or dynamic code execution were detected. |
| dist/shared/pathe.BSlhyZSM.cjs | safe | No malicious patterns detected; the file is a legitimate path manipulation library (pathe) with an inlined glob-matching helper. |
| dist/shared/pathe.M-eThtNZ.mjs | safe | The code appears to be a legitimate path manipulation and glob matching library with no malicious patterns detected. |
| dist/utils.cjs | safe | No malicious patterns detected |
| dist/utils.mjs | safe | The code implements path alias resolution utilities for the pathe package with no network, filesystem, process, or dynamic code execution concerns. |
Scanned versions of pathe
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.0.3 | No issues | 6 | Oct 6, 2026 |
Frequently asked questions
Is pathe safe to use?
Our AI source review of pathe@2.0.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does pathe contain malware?
No malware was identified in pathe@2.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was pathe checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan pathe together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in pathe@2.0.3, cost nothing.