Togoder security

npm package security report

react-remove-scroll npm package: is it safe?

No malicious code found.

No issues Version 2.7.2 Files reviewed 30 Size 52.1 KB Scanned

Summary

Togoder Security scanned the npm package react-remove-scroll@2.7.2 on Oct 6, 2026. An AI review of 30 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

Debug logging

NPS-EC9A5E5D7C03

A console.log statement prints diffx and diffy values to the console. This is a debug artifact leaking minor gesture coordinate deltas to the browser console, but it poses no exfiltration or environment risk.

dist/es2015/pinchAndZoom.js:15
low

Debug logging

NPS-4E46F113C39B

A console.log statement outputs touch delta values to the console. This is not malicious but could leak gesture data in production if debug output is visible, though it does not send data externally.

dist/es5/pinchAndZoom.js:16

Files reviewed

FileVerdictWhat the reviewer saw
dist/es2015/Combination.js safe No malicious patterns detected
dist/es2015/SideEffect.js safe No malicious patterns detected; the code is a legitimate scroll-locking utility from react-remove-scroll, with no data exfiltration, credential harvesting, obfuscation, network calls, or process spawning.
dist/es2015/UI.js safe No malicious patterns detected; the code is a legitimate React component for scroll locking.
dist/es2015/aggresiveCapture.js safe No malicious patterns detected; the code is a standard feature-detection snippet for passive event listener support.
dist/es2015/handleScroll.js safe No malicious patterns detected
dist/es2015/index.js safe Cleared by Jev triage; no further analysis needed
dist/es2015/medium.js safe No malicious patterns detected
dist/es2015/pinchAndZoom.js safe The file implements a standard touch gesture handler (pinch/zoom/move) with no network, file system, process, credential, or dynamic code execution behavior; only a benign console.log debug statement is present.
dist/es2015/sidecar.js safe Cleared by Jev triage; no further analysis needed
dist/es2015/types.js safe Cleared by Jev triage; no further analysis needed
dist/es2019/Combination.js safe Cleared by Jev triage; no further analysis needed
dist/es2019/SideEffect.js safe No malicious patterns detected
dist/es2019/UI.js safe No malicious patterns detected; the code is a legitimate React component for scroll locking with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/es2019/aggresiveCapture.js safe No malicious patterns detected; the code is a standard feature-detection snippet for passive event listener support.
dist/es2019/handleScroll.js safe No malicious patterns detected; the code is a legitimate scroll handling utility with no network, file system, process execution, or obfuscated behavior.
dist/es2019/index.js safe Cleared by Jev triage; no further analysis needed
dist/es2019/medium.js safe No malicious patterns detected
dist/es2019/pinchAndZoom.js safe No malicious patterns detected; the code implements touch gesture detection without network, filesystem, or process manipulation.
dist/es2019/sidecar.js safe Cleared by Jev triage; no further analysis needed
dist/es2019/types.js safe Cleared by Jev triage; no further analysis needed
dist/es5/Combination.js safe No malicious patterns detected
dist/es5/SideEffect.js safe No malicious patterns detected; the code is a legitimate scroll-locking side-effect component using React hooks and DOM event listeners without any data exfiltration, credential harvesting, obfuscation, or process spawning.
dist/es5/UI.js safe No malicious patterns detected; the code is a legitimate React component for scroll locking with standard prop handling and ref usage.
dist/es5/aggresiveCapture.js safe No malicious patterns detected; the code is a standard passive event listener feature detection utility.
dist/es5/handleScroll.js safe No malicious patterns detected; the code only implements scroll handling logic using standard DOM APIs.
Show 5 more files
FileVerdictWhat the reviewer saw
dist/es5/index.js safe No malicious patterns detected
dist/es5/medium.js safe The code is a minimal, non-obfuscated sidecar module initialization that imports a helper library and exports a function, with no malicious patterns detected.
dist/es5/pinchAndZoom.js safe No malicious patterns detected; only benign touch gesture logic with a minor debug console.log statement.
dist/es5/sidecar.js safe No malicious patterns detected
dist/es5/types.js safe No malicious patterns detected

Scanned versions of react-remove-scroll

VersionVerdictFilesScanned
2.7.2 No issues 30 Oct 6, 2026

Frequently asked questions

Is react-remove-scroll safe to use?

Our AI source review of react-remove-scroll@2.7.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does react-remove-scroll contain malware?

No malware was identified in react-remove-scroll@2.7.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was react-remove-scroll checked?

Togoder Security downloaded the published npm package and had an AI model read its 30 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan react-remove-scroll together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react-remove-scroll@2.7.2, cost nothing.

Related security reports