Summary
Togoder Security scanned the npm package pump@3.0.3 on Oct 4, 2026. An AI review of 3 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 4
Process Execution
NPS-11845EFBB8FE
No child_process, exec, spawn, or shell command usage is present. The only external module required is 'fs' and 'stream', used for stream testing.
Dynamic Code Execution
NPS-E669524A60BC
No eval, new Function, or dynamic require with computed paths. The require('./index') is a static relative import of the local package.
Network Activity
NPS-68C4207A20BD
No network requests or data exfiltration patterns. The script only uses local file streams and the local pump module.
File System Access
NPS-FB70268F4009
The script reads from /dev/random and writes to /dev/null, which are standard system device files on Unix-like systems. This is typical for a test file verifying stream behavior and does not represent malicious file system manipulation.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| test-browser.js | safe | No malicious patterns detected |
| test-node.js | safe | The test-node.js file is a standard stream pump test that reads from /dev/random and writes to /dev/null without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
Frequently asked questions
Is pump safe to use?
Our AI source review of pump@3.0.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does pump contain malware?
No malware was identified in pump@3.0.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was pump checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan pump together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in pump@3.0.3, cost nothing.