Togoder security

npm package security report

pathe@2.0.3 security report

No malicious code found.

No issues Version 2.0.3 Files reviewed 6 Size 32.1 KB Scanned

Summary

Togoder Security scanned the npm package pathe@2.0.3 on Oct 6, 2026. An AI review of 6 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Minified/Bundled Code

NPS-013CB71CD415

The file contains minified/bundled code (likely from a library like zeptomatch and pathe). Minification is not malicious per se, but it reduces readability. No suspicious behavior such as exfiltration, credential harvesting, or dynamic code execution was found.

dist/shared/pathe.M-eThtNZ.mjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs safe No malicious patterns detected; the code is a thin re-export wrapper for the pathe path utility library with platform delimiter handling.
dist/index.mjs safe The code is a thin wrapper around the pathe path utility library, using standard Proxy objects to expose posix/win32 variants; no malicious patterns such as network calls, credential harvesting, process spawning, or dynamic code execution were detected.
dist/shared/pathe.BSlhyZSM.cjs safe No malicious patterns detected; the file is a legitimate path manipulation library (pathe) with an inlined glob-matching helper.
dist/shared/pathe.M-eThtNZ.mjs safe The code appears to be a legitimate path manipulation and glob matching library with no malicious patterns detected.
dist/utils.cjs safe No malicious patterns detected
dist/utils.mjs safe The code implements path alias resolution utilities for the pathe package with no network, filesystem, process, or dynamic code execution concerns.

Frequently asked questions

Is pathe safe to use?

Our AI source review of pathe@2.0.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does pathe contain malware?

No malware was identified in pathe@2.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was pathe checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan pathe together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in pathe@2.0.3, cost nothing.

Related security reports