Summary
Togoder Security scanned the npm package proto-list@1.2.4 on Oct 6, 2026. An AI review of 1 source file produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Prototype pollution
NPS-F6F42883905B
The ProtoList class manipulates object prototypes via Object.setPrototypeOf / __proto__, which can lead to prototype pollution. The set and push methods allow setting arbitrary keys on the prototype chain, potentially affecting all objects inheriting from the same prototype. This is a known security risk in JavaScript.
Potential for prototype chain manipulation
NPS-459C4BF56031
The root setter and methods like push, unshift, pop, shift, and splice dynamically alter the prototype of objects in the list. This could be abused if untrusted input controls the objects or keys, leading to unexpected behavior or privilege escalation in certain contexts.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| proto-list.js | medium | The code is a utility for managing a prototype-based linked list and does not contain obvious malicious patterns, but it exposes prototype pollution risks that could be exploited if used with untrusted data. |
Scanned versions of proto-list
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.2.4 | Needs review | 1 | Oct 6, 2026 |
Frequently asked questions
Is proto-list safe to use?
No confirmed malware was found in proto-list@1.2.4, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.
Does proto-list contain malware?
No malware was identified in proto-list@1.2.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was proto-list checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan proto-list together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in proto-list@1.2.4, cost nothing.