Togoder security

npm package security report

promzard@3.0.1 security report

Critical: dangerous or likely malicious code found.

Critical risk Version 3.0.1 Files reviewed 1 Size 4.6 KB Scanned

Summary

Togoder Security scanned the npm package promzard@3.0.1 on Oct 6, 2026. An AI review of 1 source file produced 2 critical, 2 high, 1 medium severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

2
critical
2
high
1
medium
0
low

Findings 5

critical

Arbitrary code execution via file loading

NPS-985DCAFF42B5

The PromZard class reads a file (or uses an in-memory buffer via fromBuffer) and executes its contents. The file path is user-controlled (constructor parameter). This allows loading and executing any JavaScript file on the system, leading to code execution.

lib/index.js:57
critical

Dynamic code execution

NPS-7A6E46D3D7AB

The code uses vm.runInThisContext() to execute the contents of a file or buffer as JavaScript within the current context. This is effectively eval() and allows arbitrary code execution from the loaded file/buffer. If an attacker can control the file path or buffer, they can execute arbitrary code with the privileges of the process.

lib/index.js:62
high

Module loading with computed input

NPS-B2301F28C891

The code creates a new Module and uses Module._nodeModulePaths and Module._resolveFilename with a path derived from the input file. This can be abused to load arbitrary modules from attacker-controlled locations, potentially leading to further code execution or module hijacking.

lib/index.js:50
high

Exposed require function

NPS-194F268004EB

The context object passed to the executed code includes a require function bound to the module, allowing the executed script to load any module available in the Node.js environment. This could be used to access sensitive modules like child_process, fs, etc., enabling further malicious actions.

lib/index.js:58
medium

Prompt injection and callback execution

NPS-F8EAA728A0CE

The #walk method iterates over object properties and executes functions with callbacks, and processes prompts. An attacker-controlled script could define functions that are automatically invoked, leading to arbitrary code execution during the walk process.

lib/index.js:106

Files reviewed

FileVerdictWhat the reviewer saw
lib/index.js critical The code executes arbitrary JavaScript from files or buffers using vm.runInThisContext, and provides a require function to the executed code, creating a critical code execution vulnerability.

Frequently asked questions

Is promzard safe to use?

promzard@3.0.1 has 2 critical, 2 high, 1 medium severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.

Does promzard contain malware?

The latest scan of promzard (3.0.1) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.

How was promzard checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan promzard together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in promzard@3.0.1, cost nothing.

Related security reports