Togoder security

npm package security report

react npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 19.3.0 Files reviewed 24 Size 171.1 KB Scanned

Summary

Togoder Security scanned the npm package react@19.3.0 on Oct 6, 2026. An AI review of 24 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Code runs at import time

NPS-4A3976384572

The file immediately executes an IIFE at module load time (guarded only by NODE_ENV !== 'production') that calls require('react') and accesses React internals. This means importing the package has immediate side effects rather than merely exporting functions. While this is standard React development runtime behavior and not inherently malicious, it is a top-level side-effect on import worth noting.

cjs/react-compiler-runtime.development.js:13
low

Access to private/internal React internals

NPS-603510462F9C

Accesses '__CLIENT_INTERNALS_DO_NOT_USE_OR_WARN_USERS_THEY_CANNOT_UPGRADE', an explicitly private/unsupported React internal. Not malicious per se, but code relying on undocumented internals is fragile and could break or behave unexpectedly across React versions.

cjs/react-compiler-runtime.development.js:15
low

useMemoCache invocation of dispatcher

NPS-B40D68989DE4

Calls dispatcher.useMemoCache(size) which executes React's hook dispatcher. This is the intended functionality of react-compiler-runtime; no exfiltration, obfuscation, network, filesystem, or process-spawning behavior is present.

cjs/react-compiler-runtime.development.js:25

Files reviewed

FileVerdictWhat the reviewer saw
cjs/react-compiler-runtime.development.js medium The file is the legitimate React compiler runtime development build with only standard import-time hook binding; no malicious patterns such as exfiltration, credential harvesting, obfuscation, network calls, filesystem manipulation, or process spawning were found.
cjs/react-compiler-runtime.production.js safe No malicious patterns detected
cjs/react-compiler-runtime.profiling.js safe No malicious patterns detected
cjs/react-jsx-dev-runtime.development.js safe No malicious patterns detected; this is the standard React JSX development runtime with only debugging and validation logic.
cjs/react-jsx-dev-runtime.production.js safe No malicious patterns detected
cjs/react-jsx-dev-runtime.profiling.js safe This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export.
cjs/react-jsx-dev-runtime.react-server.development.js safe No malicious patterns detected; this is the legitimate React JSX development runtime for server components.
cjs/react-jsx-dev-runtime.react-server.production.js safe This is a legitimate React Server Components JSX runtime production build with no malicious patterns detected.
cjs/react-jsx-runtime.development.js safe No malicious patterns detected
cjs/react-jsx-runtime.production.js safe No malicious patterns detected
cjs/react-jsx-runtime.profiling.js safe No malicious patterns detected; this is a legitimate React JSX runtime profiling build with no network, filesystem, process, or dynamic execution activity.
cjs/react-jsx-runtime.react-server.development.js safe This is the legitimate React JSX runtime development build from Meta/Facebook with no malicious patterns detected.
cjs/react-jsx-runtime.react-server.production.js safe No malicious patterns detected in react-jsx-runtime.react-server.production.js; code is a standard production JSX runtime factory with only a benign environment check.
cjs/react.development.js safe This is the legitimate React development build with no malicious patterns detected; all dynamic code execution, network, and environment interactions are standard React internals and guardrails.
cjs/react.production.js safe No malicious patterns detected; this is the legitimate official React 19.3.0 production build with standard library functionality.
cjs/react.react-server.development.js safe This is the legitimate React 19.3.0 server-side development build from Meta, containing only standard React internals with no malicious patterns, network activity, or code execution outside the React library's expected behavior.
cjs/react.react-server.production.js safe No malicious patterns detected; this is a legitimate production build of React's react-server entry point.
compiler-runtime.js safe No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV.
index.js safe This is a standard React environment-based module export switch with no malicious patterns detected.
jsx-dev-runtime.js safe No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV.
jsx-dev-runtime.react-server.js safe No malicious patterns detected
jsx-runtime.js safe This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected.
jsx-runtime.react-server.js safe This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected.
react.react-server.js safe No malicious patterns detected

Affected version ranges

None of the 2 scanned versions of react are flagged high or critical. The latest scanned version, 19.3.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

18.3.119.3.0
VersionsVerdictCountRangeTop findings
19.3.0 Needs review 1 19.3.0
19.0.0 โ€“ 19.2.8 Not scanned 2 >=19.0.0 <=19.2.8
18.3.1 No issues 1 18.3.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of react

VersionVerdictFilesScanned
19.3.0 Needs review 24 Oct 6, 2026
18.3.1 No issues 8 Oct 4, 2026

Frequently asked questions

Is react safe to use?

No confirmed malware was found in react@19.3.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does react contain malware?

No malware was identified in react@19.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was react checked?

Togoder Security downloaded the published npm package and had an AI model read its 24 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan react together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react@19.3.0, cost nothing.

Related security reports