Summary
Togoder Security scanned the npm package react@19.3.0 on Oct 6, 2026. An AI review of 24 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Code runs at import time
NPS-4A3976384572
The file immediately executes an IIFE at module load time (guarded only by NODE_ENV !== 'production') that calls require('react') and accesses React internals. This means importing the package has immediate side effects rather than merely exporting functions. While this is standard React development runtime behavior and not inherently malicious, it is a top-level side-effect on import worth noting.
Access to private/internal React internals
NPS-603510462F9C
Accesses '__CLIENT_INTERNALS_DO_NOT_USE_OR_WARN_USERS_THEY_CANNOT_UPGRADE', an explicitly private/unsupported React internal. Not malicious per se, but code relying on undocumented internals is fragile and could break or behave unexpectedly across React versions.
useMemoCache invocation of dispatcher
NPS-B40D68989DE4
Calls dispatcher.useMemoCache(size) which executes React's hook dispatcher. This is the intended functionality of react-compiler-runtime; no exfiltration, obfuscation, network, filesystem, or process-spawning behavior is present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cjs/react-compiler-runtime.development.js | medium | The file is the legitimate React compiler runtime development build with only standard import-time hook binding; no malicious patterns such as exfiltration, credential harvesting, obfuscation, network calls, filesystem manipulation, or process spawning were found. |
| cjs/react-compiler-runtime.production.js | safe | No malicious patterns detected |
| cjs/react-compiler-runtime.profiling.js | safe | No malicious patterns detected |
| cjs/react-jsx-dev-runtime.development.js | safe | No malicious patterns detected; this is the standard React JSX development runtime with only debugging and validation logic. |
| cjs/react-jsx-dev-runtime.production.js | safe | No malicious patterns detected |
| cjs/react-jsx-dev-runtime.profiling.js | safe | This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export. |
| cjs/react-jsx-dev-runtime.react-server.development.js | safe | No malicious patterns detected; this is the legitimate React JSX development runtime for server components. |
| cjs/react-jsx-dev-runtime.react-server.production.js | safe | This is a legitimate React Server Components JSX runtime production build with no malicious patterns detected. |
| cjs/react-jsx-runtime.development.js | safe | No malicious patterns detected |
| cjs/react-jsx-runtime.production.js | safe | No malicious patterns detected |
| cjs/react-jsx-runtime.profiling.js | safe | No malicious patterns detected; this is a legitimate React JSX runtime profiling build with no network, filesystem, process, or dynamic execution activity. |
| cjs/react-jsx-runtime.react-server.development.js | safe | This is the legitimate React JSX runtime development build from Meta/Facebook with no malicious patterns detected. |
| cjs/react-jsx-runtime.react-server.production.js | safe | No malicious patterns detected in react-jsx-runtime.react-server.production.js; code is a standard production JSX runtime factory with only a benign environment check. |
| cjs/react.development.js | safe | This is the legitimate React development build with no malicious patterns detected; all dynamic code execution, network, and environment interactions are standard React internals and guardrails. |
| cjs/react.production.js | safe | No malicious patterns detected; this is the legitimate official React 19.3.0 production build with standard library functionality. |
| cjs/react.react-server.development.js | safe | This is the legitimate React 19.3.0 server-side development build from Meta, containing only standard React internals with no malicious patterns, network activity, or code execution outside the React library's expected behavior. |
| cjs/react.react-server.production.js | safe | No malicious patterns detected; this is a legitimate production build of React's react-server entry point. |
| compiler-runtime.js | safe | No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV. |
| index.js | safe | This is a standard React environment-based module export switch with no malicious patterns detected. |
| jsx-dev-runtime.js | safe | No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV. |
| jsx-dev-runtime.react-server.js | safe | No malicious patterns detected |
| jsx-runtime.js | safe | This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected. |
| jsx-runtime.react-server.js | safe | This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected. |
| react.react-server.js | safe | No malicious patterns detected |
Affected version ranges
None of the 2 scanned versions of react are flagged high or critical. The latest scanned version, 19.3.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 19.3.0 | Needs review | 1 | 19.3.0 | |
| 19.0.0 โ 19.2.8 | Not scanned | 2 | >=19.0.0 <=19.2.8 | |
| 18.3.1 | No issues | 1 | 18.3.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of react
Frequently asked questions
Is react safe to use?
No confirmed malware was found in react@19.3.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does react contain malware?
No malware was identified in react@19.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was react checked?
Togoder Security downloaded the published npm package and had an AI model read its 24 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan react together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react@19.3.0, cost nothing.