Summary
Togoder Security scanned the npm package promzard@3.0.1 on Oct 6, 2026. An AI review of 1 source file produced 2 critical, 2 high, 1 medium severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.
Findings 5
Arbitrary code execution via file loading
NPS-985DCAFF42B5
The PromZard class reads a file (or uses an in-memory buffer via fromBuffer) and executes its contents. The file path is user-controlled (constructor parameter). This allows loading and executing any JavaScript file on the system, leading to code execution.
Dynamic code execution
NPS-7A6E46D3D7AB
The code uses vm.runInThisContext() to execute the contents of a file or buffer as JavaScript within the current context. This is effectively eval() and allows arbitrary code execution from the loaded file/buffer. If an attacker can control the file path or buffer, they can execute arbitrary code with the privileges of the process.
Module loading with computed input
NPS-B2301F28C891
The code creates a new Module and uses Module._nodeModulePaths and Module._resolveFilename with a path derived from the input file. This can be abused to load arbitrary modules from attacker-controlled locations, potentially leading to further code execution or module hijacking.
Exposed require function
NPS-194F268004EB
The context object passed to the executed code includes a require function bound to the module, allowing the executed script to load any module available in the Node.js environment. This could be used to access sensitive modules like child_process, fs, etc., enabling further malicious actions.
Prompt injection and callback execution
NPS-F8EAA728A0CE
The #walk method iterates over object properties and executes functions with callbacks, and processes prompts. An attacker-controlled script could define functions that are automatically invoked, leading to arbitrary code execution during the walk process.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/index.js | critical | The code executes arbitrary JavaScript from files or buffers using vm.runInThisContext, and provides a require function to the executed code, creating a critical code execution vulnerability. |
Scanned versions of promzard
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 3.0.1 | Critical risk | 1 | Oct 6, 2026 |
Frequently asked questions
Is promzard safe to use?
promzard@3.0.1 has 2 critical, 2 high, 1 medium severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.
Does promzard contain malware?
The latest scan of promzard (3.0.1) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.
How was promzard checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan promzard together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in promzard@3.0.1, cost nothing.