Summary
Togoder Security scanned the npm package react-remove-scroll-bar@2.3.8 on Oct 6, 2026. An AI review of 12 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/es2015/component.js | safe | No malicious patterns detected; the code is a legitimate scrollbar-locking utility using only standard React and DOM APIs. |
| dist/es2015/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2015/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2015/utils.js | safe | No malicious patterns detected |
| dist/es2019/component.js | safe | No malicious patterns detected |
| dist/es2019/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es5/component.js | safe | No malicious patterns detected; the code only manipulates DOM attributes and injects scoped CSS to manage scrollbar locking. |
| dist/es5/constants.js | safe | No malicious patterns detected |
| dist/es5/index.js | safe | No malicious patterns detected; the file is a standard ES5 re-export module for the react-remove-scroll library. |
| dist/es5/utils.js | safe | No malicious patterns detected; the code only computes layout gap dimensions using standard DOM APIs with no network, filesystem, process, or dynamic execution activity. |
Scanned versions of react-remove-scroll-bar
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.3.8 | No issues | 12 | Oct 6, 2026 |
Frequently asked questions
Is react-remove-scroll-bar safe to use?
Our AI source review of react-remove-scroll-bar@2.3.8 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does react-remove-scroll-bar contain malware?
No malware was identified in react-remove-scroll-bar@2.3.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was react-remove-scroll-bar checked?
Togoder Security downloaded the published npm package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan react-remove-scroll-bar together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react-remove-scroll-bar@2.3.8, cost nothing.