Togoder security

npm package security report

proto-list@1.2.4 security report

Risky patterns found that deserve a look.

Needs review Version 1.2.4 Files reviewed 1 Size 2.2 KB Scanned

Summary

Togoder Security scanned the npm package proto-list@1.2.4 on Oct 6, 2026. An AI review of 1 source file produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
0
low

Findings 2

medium

Prototype pollution

NPS-F6F42883905B

The ProtoList class manipulates object prototypes via Object.setPrototypeOf / __proto__, which can lead to prototype pollution. The set and push methods allow setting arbitrary keys on the prototype chain, potentially affecting all objects inheriting from the same prototype. This is a known security risk in JavaScript.

proto-list.js
medium

Potential for prototype chain manipulation

NPS-459C4BF56031

The root setter and methods like push, unshift, pop, shift, and splice dynamically alter the prototype of objects in the list. This could be abused if untrusted input controls the objects or keys, leading to unexpected behavior or privilege escalation in certain contexts.

proto-list.js

Files reviewed

FileVerdictWhat the reviewer saw
proto-list.js medium The code is a utility for managing a prototype-based linked list and does not contain obvious malicious patterns, but it exposes prototype pollution risks that could be exploited if used with untrusted data.

Frequently asked questions

Is proto-list safe to use?

No confirmed malware was found in proto-list@1.2.4, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.

Does proto-list contain malware?

No malware was identified in proto-list@1.2.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was proto-list checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan proto-list together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in proto-list@1.2.4, cost nothing.

Related security reports