# pump@3.0.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:39:38.000Z
- Files reviewed: 3
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/pump
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package pump@3.0.3 on Oct 4, 2026. An AI review of 3 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Process Execution

Finding ID: `NPS-11845EFBB8FE`

File: `test-node.js`

No child_process, exec, spawn, or shell command usage is present. The only external module required is 'fs' and 'stream', used for stream testing.

### [low] Dynamic Code Execution

Finding ID: `NPS-E669524A60BC`

File: `test-node.js`

No eval, new Function, or dynamic require with computed paths. The require('./index') is a static relative import of the local package.

### [low] Network Activity

Finding ID: `NPS-68C4207A20BD`

File: `test-node.js`

No network requests or data exfiltration patterns. The script only uses local file streams and the local pump module.

### [low] File System Access

Finding ID: `NPS-FB70268F4009`

File: `test-node.js:3`

The script reads from /dev/random and writes to /dev/null, which are standard system device files on Unix-like systems. This is typical for a test file verifying stream behavior and does not represent malicious file system manipulation.

## Files reviewed

- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `test-browser.js` (safe): No malicious patterns detected
- `test-node.js` (safe): The test-node.js file is a standard stream pump test that reads from /dev/random and writes to /dev/null without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
