Togoder security

npm package security report

preact@10.24.2 security report

Risky patterns found that deserve a look.

Needs review Version 10.24.2 Files reviewed 78 Size 312.7 KB Scanned

Summary

Togoder Security scanned the npm package preact@10.24.2 on Oct 4, 2026. An AI review of 78 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

Code runs at import time

NPS-6AF7802EF0C9

The UMD wrapper executes immediately upon import/require. It reads globalThis/window/self and conditionally calls attachPreact from the global __PREACT_DEVTOOLS__ object. While typical for UMD bundles, top-level code execution on import is a notable behavior.

devtools/dist/devtools.umd.js:1
low

Global object mutation

NPS-A60E84860036

The module attaches itself to a global name (preactDevtools) and calls into a globally-named __PREACT_DEVTOOLS__ object. This is standard for devtools integration but does modify global scope.

devtools/dist/devtools.umd.js:1

Files reviewed

FileVerdictWhat the reviewer saw
devtools/dist/devtools.umd.js medium Small Preact DevTools UMD bundle with no obvious malicious behavior; only standard UMD bootstrapping and global hook attachment, though it does execute at import time.
compat/client.js safe Cleared by Jev triage; no further analysis needed
compat/client.mjs safe Cleared by Jev triage; no further analysis needed
compat/dist/compat.js safe No malicious patterns detected; the file is a legitimate Preact compatibility layer for React APIs.
compat/dist/compat.mjs safe No malicious patterns detected; this is the standard Preact compatibility layer for React.
compat/dist/compat.module.js safe No malicious patterns detected; this is the standard Preact compatibility layer for React.
compat/dist/compat.umd.js safe No malicious patterns detected; this is a legitimate Preact compatibility layer for React.
compat/jsx-dev-runtime.js safe No malicious patterns detected
compat/jsx-dev-runtime.mjs safe No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
compat/jsx-runtime.js safe No malicious patterns detected
compat/jsx-runtime.mjs safe No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
compat/scheduler.js safe Cleared by Jev triage; no further analysis needed
compat/scheduler.mjs safe Cleared by Jev triage; no further analysis needed
compat/server.browser.js safe Cleared by Jev triage; no further analysis needed
compat/server.js safe No malicious patterns detected; the file only wraps preact-render-to-string module exports.
compat/server.mjs safe Cleared by Jev triage; no further analysis needed
compat/src/Children.js safe Cleared by Jev triage; no further analysis needed
compat/src/PureComponent.js safe No malicious patterns detected; the code is a standard PureComponent compatibility shim for Preact.
compat/src/forwardRef.js safe No malicious patterns detected; the code is a legitimate Preact compatibility shim implementing React.forwardRef semantics.
compat/src/index.js safe Cleared by Jev triage; no further analysis needed
compat/src/memo.js safe Cleared by Jev triage; no further analysis needed
compat/src/portals.js safe No malicious patterns detected; the code is a legitimate Preact Portal implementation with no network, filesystem, process, or obfuscation concerns.
compat/src/render.js safe No malicious patterns detected; the file is a standard Preact-React compatibility layer with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
compat/src/suspense-list.js safe No malicious patterns detected; the code is a legitimate Preact SuspenseList implementation with no security concerns.
compat/src/suspense.js safe No malicious patterns detected; the code is a legitimate Preact compat module implementing Suspense/lazy functionality.
Show 53 more files
FileVerdictWhat the reviewer saw
compat/src/util.js safe Cleared by Jev triage; no further analysis needed
compat/test-utils.js safe Cleared by Jev triage; no further analysis needed
debug/dist/debug.js safe No malicious patterns detected; the code is a standard Preact debug utility that adds development-time warnings and does not exfiltrate data or execute untrusted code.
debug/dist/debug.mjs safe No malicious patterns detected; the code is a legitimate Preact debug utility that only performs console warnings and error checks.
debug/dist/debug.module.js safe No malicious patterns detected; the code is a legitimate Preact debug utility that only performs console warnings and error checks.
debug/dist/debug.umd.js safe No malicious patterns detected; this is a legitimate Preact debug utility that warns about common React/Preact development mistakes.
debug/src/check-props.js safe Cleared by Jev triage; no further analysis needed
debug/src/component-stack.js safe No malicious patterns detected
debug/src/constants.js safe Cleared by Jev triage; no further analysis needed
debug/src/debug.js safe No malicious patterns detected
debug/src/index.js safe No malicious patterns detected; the file only imports debug utilities and Preact devtools, then exports a reset function.
debug/src/util.js safe Cleared by Jev triage; no further analysis needed
devtools/dist/devtools.js safe No malicious patterns detected
devtools/dist/devtools.mjs safe No malicious patterns detected
devtools/dist/devtools.module.js safe No malicious patterns detected
devtools/src/devtools.js safe No malicious patterns detected; the code only integrates with a pre-existing global Preact DevTools hook.
devtools/src/index.js safe No malicious patterns detected
dist/preact.js safe No malicious patterns detected; this is a minified build of the Preact library with standard rendering and event handling code.
dist/preact.min.module.js safe This is the minified Preact library (expected v10.x) implementing a virtual DOM renderer; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, or process spawning were detected.
dist/preact.min.umd.js safe This is a minified UMD build of Preact, a legitimate JavaScript library, with no malicious patterns detected.
dist/preact.mjs safe This is the minified distribution build of Preact, a legitimate JavaScript UI library; no malicious patterns, obfuscation, exfiltration, or suspicious behavior were detected.
dist/preact.module.js safe This is the minified distribution build of Preact, a legitimate JavaScript UI library; no malicious patterns, obfuscation, exfiltration, or suspicious behavior were detected.
dist/preact.umd.js safe No malicious patterns detected
hooks/dist/hooks.js safe No malicious patterns detected; the code is a standard Preact hooks implementation without data exfiltration, obfuscation, credential harvesting, or suspicious system/network activity.
hooks/dist/hooks.mjs safe No malicious patterns detected; the code is a minified Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
hooks/dist/hooks.module.js safe No malicious patterns detected; the code is a minified Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
hooks/dist/hooks.umd.js safe No malicious patterns detected; this is the standard Preact Hooks UMD library.
hooks/src/index.js safe No malicious patterns detected
jsx-runtime/dist/jsxRuntime.js safe This file is the standard Preact JSX runtime implementation and contains no malicious patterns, network calls, process spawning, or credential harvesting.
jsx-runtime/dist/jsxRuntime.mjs safe No malicious patterns detected; the code is a standard Preact JSX runtime implementation with no network, filesystem, process, or dynamic code execution activity.
jsx-runtime/dist/jsxRuntime.module.js safe No malicious patterns detected; the code is a standard Preact JSX runtime implementation with no network, filesystem, process, or dynamic code execution activity.
jsx-runtime/dist/jsxRuntime.umd.js safe No malicious patterns detected; this is the standard Preact JSX runtime UMD build with only benign escaping and vnode creation logic.
jsx-runtime/src/index.js safe Cleared by Jev triage; no further analysis needed
jsx-runtime/src/utils.js safe Cleared by Jev triage; no further analysis needed
src/cjs.js safe No malicious patterns detected
src/clone-element.js safe Cleared by Jev triage; no further analysis needed
src/component.js safe Cleared by Jev triage; no further analysis needed
src/constants.js safe Cleared by Jev triage; no further analysis needed
src/create-context.js safe Cleared by Jev triage; no further analysis needed
src/create-element.js safe Cleared by Jev triage; no further analysis needed
src/diff/catch-error.js safe Cleared by Jev triage; no further analysis needed
src/diff/children.js safe Cleared by Jev triage; no further analysis needed
src/diff/index.js safe No malicious patterns detected
src/diff/props.js safe Cleared by Jev triage; no further analysis needed
src/index.js safe Cleared by Jev triage; no further analysis needed
src/options.js safe Cleared by Jev triage; no further analysis needed
src/render.js safe Cleared by Jev triage; no further analysis needed
src/util.js safe Cleared by Jev triage; no further analysis needed
test-utils/dist/testUtils.js safe No malicious patterns detected
test-utils/dist/testUtils.mjs safe This is legitimate Preact testing utility code that provides act() and setupRerender() functions for test environments, with no malicious patterns detected.
test-utils/dist/testUtils.module.js safe This is legitimate Preact testing utility code that provides act() and setupRerender() functions for test environments, with no malicious patterns detected.
test-utils/dist/testUtils.umd.js safe No malicious patterns detected
test-utils/src/index.js safe No malicious patterns detected; the code is a legitimate Preact test utility for flushing renders and effects.

Affected version ranges

None of the 2 scanned versions of preact are flagged high or critical. The latest scanned version, 10.29.8, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

10.24.210.29.8
VersionsVerdictCountRangeTop findings
10.29.8 Needs review 1 10.29.8
10.24.3 Not scanned 1 10.24.3
10.24.2 Needs review 1 10.24.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of preact

VersionVerdictFilesScanned
10.29.8 Needs review 80 Oct 6, 2026
10.24.2 Needs review 78 Oct 4, 2026

Frequently asked questions

Is preact safe to use?

No confirmed malware was found in preact@10.24.2, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does preact contain malware?

No malware was identified in preact@10.24.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was preact checked?

Togoder Security downloaded the published npm package and had an AI model read its 78 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan preact together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in preact@10.24.2, cost nothing.

Related security reports