Summary
Togoder Security scanned the npm package preact@10.29.8 on Oct 6, 2026. An AI review of 80 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
debug/development tooling
NPS-0388FDBF0C4C
This file is the official Preact debug package (preact/debug) compiled to ESM. It only contains development-time warnings, prop-type validation, and DOM nesting checks. It does not perform network requests, spawn processes, read credentials, execute dynamic code, or manipulate the file system.
debug/development tooling
NPS-0388FDBF0C4C
This file is the official Preact debug package (preact/debug) compiled to ESM. It only contains development-time warnings, prop-type validation, and DOM nesting checks. It does not perform network requests, spawn processes, read credentials, execute dynamic code, or manipulate the file system.
Module import side effects
NPS-91D9BD86A312
The file imports 'preact/devtools' which is typically a development-only module. Importing devtools can attach global hooks (e.g., to window) and expose internal component state. In a production bundle this could unintentionally expose debug/devtools interfaces if not properly tree-shaken.
Top-level code execution on import
NPS-AF323E193703
initDebug() is called at module import time, which runs code immediately when the module is loaded. While this is a common pattern for debug initialization, it means any side effects from initDebug execute during import without explicit user action.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| debug/src/index.js | medium | The file contains only legitimate Preact debug initialization and exports with no malicious patterns; minor concerns are import-time side effects typical of debug tooling. |
| compat/client.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/client.mjs | safe | Cleared by Jev triage; no further analysis needed |
| compat/dist/compat.js | safe | This is the legitimate Preact compatibility layer for React, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized process execution. |
| compat/dist/compat.mjs | safe | This is the official preact/compat build (v18.3.1), containing only React compatibility shims and no malicious patterns. |
| compat/dist/compat.module.js | safe | This is the official preact/compat build (v18.3.1), containing only React compatibility shims and no malicious patterns. |
| compat/dist/compat.umd.js | safe | No malicious patterns detected; the file is a standard Preact compatibility layer for React-like APIs. |
| compat/jsx-dev-runtime.js | safe | No malicious patterns detected |
| compat/jsx-dev-runtime.mjs | safe | No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation. |
| compat/jsx-runtime.js | safe | No malicious patterns detected |
| compat/jsx-runtime.mjs | safe | No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation. |
| compat/scheduler.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/scheduler.mjs | safe | Cleared by Jev triage; no further analysis needed |
| compat/server.browser.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/server.js | safe | No malicious patterns detected; the file is a legitimate compatibility shim for Preact server-side rendering. |
| compat/server.mjs | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/Children.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/PureComponent.js | safe | No malicious patterns detected; the code is a standard PureComponent compatibility shim for Preact. |
| compat/src/forwardRef.js | safe | No malicious patterns detected; the code is a standard Preact forwardRef compatibility shim with no network, filesystem, process, or dynamic execution activity. |
| compat/src/hooks.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/memo.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/src/portals.js | safe | No malicious patterns detected; the code is a standard Preact portal implementation with no exfiltration, credential harvesting, obfuscation, or other security concerns. |
| compat/src/render.js | safe | This is the Preact compatibility layer (preact/compat) implementing React API compatibility; no malicious patterns detected. |
| compat/src/suspense-list.js | safe | No malicious patterns detected; the code is a legitimate Preact SuspenseList implementation with no security concerns. |
Show 55 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| compat/src/suspense.js | safe | This is legitimate Preact Suspense compatibility code with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| compat/src/util.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/test-utils.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/test-utils.mjs | safe | Cleared by Jev triage; no further analysis needed |
| debug/dist/debug.js | safe | This is the Preact debug build providing development-time warnings and validation—no malicious patterns, network calls, credential access, or dynamic code execution detected. |
| debug/dist/debug.mjs | safe | The file is the legitimate Preact debug module containing only development-time diagnostics and no malicious patterns. |
| debug/dist/debug.module.js | safe | The file is the legitimate Preact debug module containing only development-time diagnostics and no malicious patterns. |
| debug/dist/debug.umd.js | safe | No malicious patterns detected; the code is a legitimate Preact debug utility that only adds development warnings and does not perform data exfiltration, environment harvesting, code execution, or network requests. |
| debug/src/check-props.js | safe | Cleared by Jev triage; no further analysis needed |
| debug/src/component-stack.js | safe | No malicious patterns detected |
| debug/src/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| debug/src/debug.js | safe | No malicious patterns detected in the debug module; the code only provides development-time validation, warnings, and error handling for the Preact framework. |
| debug/src/util.js | safe | Cleared by Jev triage; no further analysis needed |
| devtools/dist/devtools.js | safe | No malicious patterns detected |
| devtools/dist/devtools.mjs | safe | This is a minified Preact DevTools integration module that only registers a hook name and attaches to the global Preact DevTools object; no malicious patterns detected. |
| devtools/dist/devtools.module.js | safe | This is a minified Preact DevTools integration module that only registers a hook name and attaches to the global Preact DevTools object; no malicious patterns detected. |
| devtools/dist/devtools.umd.js | safe | No malicious patterns detected; the code is a standard Preact DevTools UMD bundle that only attaches a devtools hook and adds a hook name. |
| devtools/src/devtools.js | safe | The code is a standard Preact DevTools integration hook that only conditionally attaches devtools to a global object with no malicious patterns. |
| devtools/src/index.js | safe | No malicious patterns detected |
| dist/preact.js | safe | No malicious patterns detected; this is the standard minified Preact library with no data exfiltration, obfuscated payloads, or suspicious behavior. |
| dist/preact.min.module.js | safe | This is the official Preact library minified bundle; it contains no malicious patterns, network exfiltration, credential harvesting, obfuscated payloads, or suspicious process execution. |
| dist/preact.min.umd.js | safe | This is the minified UMD build of the Preact library, a legitimate JavaScript UI framework, with no malicious patterns detected. |
| dist/preact.mjs | safe | This is the minified distribution of the Preact library, containing only legitimate UI rendering logic with no malicious patterns or suspicious behavior. |
| dist/preact.module.js | safe | This is the minified distribution of the Preact library, containing only legitimate UI rendering logic with no malicious patterns or suspicious behavior. |
| dist/preact.umd.js | safe | This is the official Preact UMD distribution and contains only standard framework code with no malicious patterns detected. |
| hooks/dist/hooks.js | safe | No malicious patterns detected; this is a minified build of the Preact hooks library with no obfuscation, network calls, filesystem access, or process spawning. |
| hooks/dist/hooks.mjs | safe | No malicious patterns detected; the file is a standard Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity. |
| hooks/dist/hooks.module.js | safe | No malicious patterns detected; the file is a standard Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity. |
| hooks/dist/hooks.umd.js | safe | No malicious patterns detected |
| hooks/src/index.js | safe | This is the legitimate Preact hooks implementation from the official preact package, containing no malicious patterns such as data exfiltration, credential harvesting, code execution, or network activity. |
| jsx-runtime/dist/jsxRuntime.js | safe | No malicious patterns detected |
| jsx-runtime/dist/jsxRuntime.mjs | safe | No malicious patterns detected; the file is a standard Preact JSX runtime with only benign escaping, VNode creation, and attribute serialization helpers. |
| jsx-runtime/dist/jsxRuntime.module.js | safe | No malicious patterns detected; the file is a standard Preact JSX runtime with only benign escaping, VNode creation, and attribute serialization helpers. |
| jsx-runtime/dist/jsxRuntime.umd.js | safe | This is the Preact JSX runtime UMD bundle and contains no malicious patterns; all functionality is limited to JSX creation and attribute escaping. |
| jsx-runtime/src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| jsx-runtime/src/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| src/cjs.js | safe | No malicious patterns detected |
| src/clone-element.js | safe | Cleared by Jev triage; no further analysis needed |
| src/component.js | safe | Cleared by Jev triage; no further analysis needed |
| src/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| src/create-context.js | safe | Cleared by Jev triage; no further analysis needed |
| src/create-element.js | safe | Cleared by Jev triage; no further analysis needed |
| src/diff/catch-error.js | safe | Cleared by Jev triage; no further analysis needed |
| src/diff/children.js | safe | Cleared by Jev triage; no further analysis needed |
| src/diff/index.js | safe | No malicious patterns detected |
| src/diff/props.js | safe | Cleared by Jev triage; no further analysis needed |
| src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| src/options.js | safe | Cleared by Jev triage; no further analysis needed |
| src/render.js | safe | Cleared by Jev triage; no further analysis needed |
| src/util.js | safe | Cleared by Jev triage; no further analysis needed |
| test-utils/dist/testUtils.js | safe | No malicious patterns detected; code is a standard Preact test utility for controlling rendering timing. |
| test-utils/dist/testUtils.mjs | safe | No malicious patterns detected; the code is a Preact test utility that temporarily intercepts rendering and requestAnimationFrame, with no network, filesystem, process, or credential access. |
| test-utils/dist/testUtils.module.js | safe | No malicious patterns detected; the code is a Preact test utility that temporarily intercepts rendering and requestAnimationFrame, with no network, filesystem, process, or credential access. |
| test-utils/dist/testUtils.umd.js | safe | No malicious patterns detected; the code is a legitimate Preact test utility implementing act() and rerender helpers. |
| test-utils/src/index.js | safe | No malicious patterns detected; this is a legitimate Preact test utility for managing render queues and act() semantics. |
Affected version ranges
None of the 2 scanned versions of preact are flagged high or critical. The latest scanned version, 10.29.8, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 10.29.8 | Needs review | 1 | 10.29.8 | |
| 10.24.3 | Not scanned | 1 | 10.24.3 | |
| 10.24.2 | Needs review | 1 | 10.24.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of preact
Frequently asked questions
Is preact safe to use?
No confirmed malware was found in preact@10.29.8, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does preact contain malware?
No malware was identified in preact@10.29.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was preact checked?
Togoder Security downloaded the published npm package and had an AI model read its 80 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan preact together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in preact@10.29.8, cost nothing.