Summary
Togoder Security scanned the npm package preact@10.24.2 on Oct 4, 2026. An AI review of 78 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Code runs at import time
NPS-6AF7802EF0C9
The UMD wrapper executes immediately upon import/require. It reads globalThis/window/self and conditionally calls attachPreact from the global __PREACT_DEVTOOLS__ object. While typical for UMD bundles, top-level code execution on import is a notable behavior.
Global object mutation
NPS-A60E84860036
The module attaches itself to a global name (preactDevtools) and calls into a globally-named __PREACT_DEVTOOLS__ object. This is standard for devtools integration but does modify global scope.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| devtools/dist/devtools.umd.js | medium | Small Preact DevTools UMD bundle with no obvious malicious behavior; only standard UMD bootstrapping and global hook attachment, though it does execute at import time. |
| compat/client.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/client.mjs | safe | Cleared by Jev triage; no further analysis needed |
| compat/dist/compat.js | safe | No malicious patterns detected; the file is a legitimate Preact compatibility layer for React APIs. |
| compat/dist/compat.mjs | safe | No malicious patterns detected; this is the standard Preact compatibility layer for React. |
| compat/dist/compat.module.js | safe | No malicious patterns detected; this is the standard Preact compatibility layer for React. |
| compat/dist/compat.umd.js | safe | No malicious patterns detected; this is a legitimate Preact compatibility layer for React. |
| compat/jsx-dev-runtime.js | safe | No malicious patterns detected |
| compat/jsx-dev-runtime.mjs | safe | No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation. |
| compat/jsx-runtime.js | safe | No malicious patterns detected |
| compat/jsx-runtime.mjs | safe | No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation. |
| compat/scheduler.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/scheduler.mjs | safe | Cleared by Jev triage; no further analysis needed |
| compat/server.browser.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/server.js | safe | No malicious patterns detected; the file only wraps preact-render-to-string module exports. |
| compat/server.mjs | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/Children.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/PureComponent.js | safe | No malicious patterns detected; the code is a standard PureComponent compatibility shim for Preact. |
| compat/src/forwardRef.js | safe | No malicious patterns detected; the code is a legitimate Preact compatibility shim implementing React.forwardRef semantics. |
| compat/src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/memo.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/portals.js | safe | No malicious patterns detected; the code is a legitimate Preact Portal implementation with no network, filesystem, process, or obfuscation concerns. |
| compat/src/render.js | safe | No malicious patterns detected; the file is a standard Preact-React compatibility layer with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| compat/src/suspense-list.js | safe | No malicious patterns detected; the code is a legitimate Preact SuspenseList implementation with no security concerns. |
| compat/src/suspense.js | safe | No malicious patterns detected; the code is a legitimate Preact compat module implementing Suspense/lazy functionality. |
Show 53 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| compat/src/util.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/test-utils.js | safe | Cleared by Jev triage; no further analysis needed |
| debug/dist/debug.js | safe | No malicious patterns detected; the code is a standard Preact debug utility that adds development-time warnings and does not exfiltrate data or execute untrusted code. |
| debug/dist/debug.mjs | safe | No malicious patterns detected; the code is a legitimate Preact debug utility that only performs console warnings and error checks. |
| debug/dist/debug.module.js | safe | No malicious patterns detected; the code is a legitimate Preact debug utility that only performs console warnings and error checks. |
| debug/dist/debug.umd.js | safe | No malicious patterns detected; this is a legitimate Preact debug utility that warns about common React/Preact development mistakes. |
| debug/src/check-props.js | safe | Cleared by Jev triage; no further analysis needed |
| debug/src/component-stack.js | safe | No malicious patterns detected |
| debug/src/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| debug/src/debug.js | safe | No malicious patterns detected |
| debug/src/index.js | safe | No malicious patterns detected; the file only imports debug utilities and Preact devtools, then exports a reset function. |
| debug/src/util.js | safe | Cleared by Jev triage; no further analysis needed |
| devtools/dist/devtools.js | safe | No malicious patterns detected |
| devtools/dist/devtools.mjs | safe | No malicious patterns detected |
| devtools/dist/devtools.module.js | safe | No malicious patterns detected |
| devtools/src/devtools.js | safe | No malicious patterns detected; the code only integrates with a pre-existing global Preact DevTools hook. |
| devtools/src/index.js | safe | No malicious patterns detected |
| dist/preact.js | safe | No malicious patterns detected; this is a minified build of the Preact library with standard rendering and event handling code. |
| dist/preact.min.module.js | safe | This is the minified Preact library (expected v10.x) implementing a virtual DOM renderer; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, or process spawning were detected. |
| dist/preact.min.umd.js | safe | This is a minified UMD build of Preact, a legitimate JavaScript library, with no malicious patterns detected. |
| dist/preact.mjs | safe | This is the minified distribution build of Preact, a legitimate JavaScript UI library; no malicious patterns, obfuscation, exfiltration, or suspicious behavior were detected. |
| dist/preact.module.js | safe | This is the minified distribution build of Preact, a legitimate JavaScript UI library; no malicious patterns, obfuscation, exfiltration, or suspicious behavior were detected. |
| dist/preact.umd.js | safe | No malicious patterns detected |
| hooks/dist/hooks.js | safe | No malicious patterns detected; the code is a standard Preact hooks implementation without data exfiltration, obfuscation, credential harvesting, or suspicious system/network activity. |
| hooks/dist/hooks.mjs | safe | No malicious patterns detected; the code is a minified Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity. |
| hooks/dist/hooks.module.js | safe | No malicious patterns detected; the code is a minified Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity. |
| hooks/dist/hooks.umd.js | safe | No malicious patterns detected; this is the standard Preact Hooks UMD library. |
| hooks/src/index.js | safe | No malicious patterns detected |
| jsx-runtime/dist/jsxRuntime.js | safe | This file is the standard Preact JSX runtime implementation and contains no malicious patterns, network calls, process spawning, or credential harvesting. |
| jsx-runtime/dist/jsxRuntime.mjs | safe | No malicious patterns detected; the code is a standard Preact JSX runtime implementation with no network, filesystem, process, or dynamic code execution activity. |
| jsx-runtime/dist/jsxRuntime.module.js | safe | No malicious patterns detected; the code is a standard Preact JSX runtime implementation with no network, filesystem, process, or dynamic code execution activity. |
| jsx-runtime/dist/jsxRuntime.umd.js | safe | No malicious patterns detected; this is the standard Preact JSX runtime UMD build with only benign escaping and vnode creation logic. |
| jsx-runtime/src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| jsx-runtime/src/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| src/cjs.js | safe | No malicious patterns detected |
| src/clone-element.js | safe | Cleared by Jev triage; no further analysis needed |
| src/component.js | safe | Cleared by Jev triage; no further analysis needed |
| src/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| src/create-context.js | safe | Cleared by Jev triage; no further analysis needed |
| src/create-element.js | safe | Cleared by Jev triage; no further analysis needed |
| src/diff/catch-error.js | safe | Cleared by Jev triage; no further analysis needed |
| src/diff/children.js | safe | Cleared by Jev triage; no further analysis needed |
| src/diff/index.js | safe | No malicious patterns detected |
| src/diff/props.js | safe | Cleared by Jev triage; no further analysis needed |
| src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| src/options.js | safe | Cleared by Jev triage; no further analysis needed |
| src/render.js | safe | Cleared by Jev triage; no further analysis needed |
| src/util.js | safe | Cleared by Jev triage; no further analysis needed |
| test-utils/dist/testUtils.js | safe | No malicious patterns detected |
| test-utils/dist/testUtils.mjs | safe | This is legitimate Preact testing utility code that provides act() and setupRerender() functions for test environments, with no malicious patterns detected. |
| test-utils/dist/testUtils.module.js | safe | This is legitimate Preact testing utility code that provides act() and setupRerender() functions for test environments, with no malicious patterns detected. |
| test-utils/dist/testUtils.umd.js | safe | No malicious patterns detected |
| test-utils/src/index.js | safe | No malicious patterns detected; the code is a legitimate Preact test utility for flushing renders and effects. |
Affected version ranges
None of the 2 scanned versions of preact are flagged high or critical. The latest scanned version, 10.29.8, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 10.29.8 | Needs review | 1 | 10.29.8 | |
| 10.24.3 | Not scanned | 1 | 10.24.3 | |
| 10.24.2 | Needs review | 1 | 10.24.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of preact
Frequently asked questions
Is preact safe to use?
No confirmed malware was found in preact@10.24.2, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does preact contain malware?
No malware was identified in preact@10.24.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was preact checked?
Togoder Security downloaded the published npm package and had an AI model read its 78 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan preact together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in preact@10.24.2, cost nothing.