Summary
Togoder Security scanned the npm package react-redux@9.2.0 on Oct 6, 2026. An AI review of 37 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
Global symbol usage
NPS-2B196AB3257B
The code uses Symbol.for('react-redux-context') and a globalThis-based map to cache React contexts. While this is unusual, it is a known technique to deduplicate contexts across multiple copies of react-redux. It does not exfiltrate data, access credentials, or execute dynamic code.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/cjs/index.js | safe | No malicious patterns detected |
| dist/cjs/react-redux.development.cjs | safe | This is the legitimate React-Redux library distribution file with no malicious patterns detected; all code relates to standard React state management functionality. |
| dist/cjs/react-redux.production.min.cjs | safe | No malicious patterns detected; the file is the standard minified production build of react-redux with no data exfiltration, credential harvesting, obfuscated payloads, or dynamic code execution. |
| dist/react-redux.browser.mjs | safe | No malicious patterns detected in the provided React-Redux library code. |
| dist/react-redux.legacy-esm.js | safe | No malicious patterns detected; the code is the legitimate compiled output of the react-redux library with normal React and Redux integration behavior. |
| dist/react-redux.mjs | safe | This is the legitimate react-redux library source with no malicious patterns detected. |
| dist/rsc.mjs | safe | No malicious patterns detected; the code is a standard React-Redux RSC compatibility shim with shallow equality utility and no network, filesystem, process, or dynamic execution behavior. |
| src/components/Context.ts | safe | No malicious patterns detected; the code is a legitimate React Redux context implementation with only a low-risk global caching pattern. |
| src/components/Provider.tsx | safe | No malicious patterns detected |
| src/components/connect.tsx | safe | No malicious patterns detected; this is the standard react-redux connect implementation. |
| src/connect/invalidArgFactory.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/connect/mapDispatchToProps.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/connect/mapStateToProps.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/connect/mergeProps.ts | safe | No malicious patterns detected |
| src/connect/selectorFactory.ts | safe | This is a standard React-Redux connect selector factory implementation with no malicious patterns detected. |
| src/connect/verifySubselectors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/connect/wrapMapToProps.ts | safe | No malicious patterns detected |
| src/exports.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/hooks/useDispatch.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/hooks/useReduxContext.ts | safe | No malicious patterns detected |
| src/hooks/useSelector.ts | safe | No malicious patterns detected in the useSelector hook implementation; it is a standard React-Redux selector hook with development-only warnings. |
| src/hooks/useStore.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index-rsc.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/types.ts | safe | Cleared by Jev triage; no further analysis needed |
Show 12 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/utils/Subscription.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/batch.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/bindActionCreators.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/hoistStatics.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/isPlainObject.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/react-is.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/react.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/shallowEqual.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/useIsomorphicLayoutEffect.ts | safe | No malicious patterns detected; the file is a standard React hook utility for isomorphic layout effects with no network, file system, process, or obfuscation concerns. |
| src/utils/useSyncExternalStore.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/verifyPlainObject.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/warning.ts | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of react-redux
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 9.2.0 | No issues | 37 | Oct 6, 2026 |
Frequently asked questions
Is react-redux safe to use?
Our AI source review of react-redux@9.2.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does react-redux contain malware?
No malware was identified in react-redux@9.2.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was react-redux checked?
Togoder Security downloaded the published npm package and had an AI model read its 37 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan react-redux together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react-redux@9.2.0, cost nothing.