Togoder security

npm package security report

pump@3.0.3 security report

No malicious code found.

No issues Version 3.0.3 Files reviewed 3 Size 4.4 KB Scanned

Summary

Togoder Security scanned the npm package pump@3.0.3 on Oct 4, 2026. An AI review of 3 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
4
low

Findings 4

low

Process Execution

NPS-11845EFBB8FE

No child_process, exec, spawn, or shell command usage is present. The only external module required is 'fs' and 'stream', used for stream testing.

test-node.js
low

Dynamic Code Execution

NPS-E669524A60BC

No eval, new Function, or dynamic require with computed paths. The require('./index') is a static relative import of the local package.

test-node.js
low

Network Activity

NPS-68C4207A20BD

No network requests or data exfiltration patterns. The script only uses local file streams and the local pump module.

test-node.js
low

File System Access

NPS-FB70268F4009

The script reads from /dev/random and writes to /dev/null, which are standard system device files on Unix-like systems. This is typical for a test file verifying stream behavior and does not represent malicious file system manipulation.

test-node.js:3

Files reviewed

FileVerdictWhat the reviewer saw
index.js safe Cleared by Jev triage; no further analysis needed
test-browser.js safe No malicious patterns detected
test-node.js safe The test-node.js file is a standard stream pump test that reads from /dev/random and writes to /dev/null without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.

Frequently asked questions

Is pump safe to use?

Our AI source review of pump@3.0.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does pump contain malware?

No malware was identified in pump@3.0.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was pump checked?

Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan pump together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in pump@3.0.3, cost nothing.

Related security reports