Summary
Togoder Security scanned the npm package rc@1.2.8 on Oct 4, 2026. An AI review of 4 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Potential undefined variable issue
NPS-E8E36CF6929D
The variable 'home' is assigned from process.env.HOME or process.env.USERPROFILE, but if neither is set, home becomes undefined. The subsequent check 'if (home)' guards against this, but it's a potential edge case.
Environment variable harvesting
NPS-372ACB5643AD
The code reads environment variables including process.env.HOME, process.env.USERPROFILE, and dynamically constructs and reads environment variables prefixed with the package name (cc.env(name + '_')). This is legitimate for a configuration loader (rc) but could theoretically leak sensitive env vars if misused.
Dynamic module loading with external input
NPS-5B764319BC5B
The code requires 'minimist' and 'deep-extend' modules and uses cc.parse (possibly a custom parser). It also processes configuration files and command-line arguments dynamically, which could be exploited if the parser has vulnerabilities.
File system access outside package scope
NPS-5680BE855836
The module reads configuration files from system and user directories including /etc/<name>/config, /etc/<name>rc, ~/.config/<name>/config, ~/.config/<name>, ~/.<name>/config, ~/.<name>rc, and current directory. While this is the intended behavior of an rc configuration loader, it accesses files outside the package scope.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | The code appears to be a legitimate configuration loader (rc) that reads config files and environment variables, with no clear malicious patterns such as data exfiltration or code execution, but it does access sensitive file system locations and environment variables as part of its normal operation. |
| browser.js | safe | Cleared by Jev triage; no further analysis needed |
| cli.js | safe | No malicious patterns detected; the CLI simply loads the local index module and prints its result as JSON. |
| lib/utils.js | safe | No malicious patterns detected |
Scanned versions of rc
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.2.8 | Needs review | 4 | Oct 4, 2026 |
Frequently asked questions
Is rc safe to use?
No confirmed malware was found in rc@1.2.8, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does rc contain malware?
No malware was identified in rc@1.2.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was rc checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan rc together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in rc@1.2.8, cost nothing.