Togoder security

npm package security report

rc npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.2.8 Files reviewed 4 Size 4.4 KB Scanned

Summary

Togoder Security scanned the npm package rc@1.2.8 on Oct 4, 2026. An AI review of 4 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

Potential undefined variable issue

NPS-E8E36CF6929D

The variable 'home' is assigned from process.env.HOME or process.env.USERPROFILE, but if neither is set, home becomes undefined. The subsequent check 'if (home)' guards against this, but it's a potential edge case.

index.js:5
low

Environment variable harvesting

NPS-372ACB5643AD

The code reads environment variables including process.env.HOME, process.env.USERPROFILE, and dynamically constructs and reads environment variables prefixed with the package name (cc.env(name + '_')). This is legitimate for a configuration loader (rc) but could theoretically leak sensitive env vars if misused.

index.js:7
low

Dynamic module loading with external input

NPS-5B764319BC5B

The code requires 'minimist' and 'deep-extend' modules and uses cc.parse (possibly a custom parser). It also processes configuration files and command-line arguments dynamically, which could be exploited if the parser has vulnerabilities.

index.js:12
low

File system access outside package scope

NPS-5680BE855836

The module reads configuration files from system and user directories including /etc/<name>/config, /etc/<name>rc, ~/.config/<name>/config, ~/.config/<name>, ~/.<name>/config, ~/.<name>rc, and current directory. While this is the intended behavior of an rc configuration loader, it accesses files outside the package scope.

index.js:32

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The code appears to be a legitimate configuration loader (rc) that reads config files and environment variables, with no clear malicious patterns such as data exfiltration or code execution, but it does access sensitive file system locations and environment variables as part of its normal operation.
browser.js safe Cleared by Jev triage; no further analysis needed
cli.js safe No malicious patterns detected; the CLI simply loads the local index module and prints its result as JSON.
lib/utils.js safe No malicious patterns detected

Scanned versions of rc

VersionVerdictFilesScanned
1.2.8 Needs review 4 Oct 4, 2026

Frequently asked questions

Is rc safe to use?

No confirmed malware was found in rc@1.2.8, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does rc contain malware?

No malware was identified in rc@1.2.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was rc checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan rc together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in rc@1.2.8, cost nothing.

Related security reports