Summary
Togoder Security scanned the npm package react-remove-scroll@2.7.2 on Oct 6, 2026. An AI review of 30 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
Debug logging
NPS-EC9A5E5D7C03
A console.log statement prints diffx and diffy values to the console. This is a debug artifact leaking minor gesture coordinate deltas to the browser console, but it poses no exfiltration or environment risk.
Debug logging
NPS-4E46F113C39B
A console.log statement outputs touch delta values to the console. This is not malicious but could leak gesture data in production if debug output is visible, though it does not send data externally.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/es2015/Combination.js | safe | No malicious patterns detected |
| dist/es2015/SideEffect.js | safe | No malicious patterns detected; the code is a legitimate scroll-locking utility from react-remove-scroll, with no data exfiltration, credential harvesting, obfuscation, network calls, or process spawning. |
| dist/es2015/UI.js | safe | No malicious patterns detected; the code is a legitimate React component for scroll locking. |
| dist/es2015/aggresiveCapture.js | safe | No malicious patterns detected; the code is a standard feature-detection snippet for passive event listener support. |
| dist/es2015/handleScroll.js | safe | No malicious patterns detected |
| dist/es2015/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2015/medium.js | safe | No malicious patterns detected |
| dist/es2015/pinchAndZoom.js | safe | The file implements a standard touch gesture handler (pinch/zoom/move) with no network, file system, process, credential, or dynamic code execution behavior; only a benign console.log debug statement is present. |
| dist/es2015/sidecar.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2015/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/Combination.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/SideEffect.js | safe | No malicious patterns detected |
| dist/es2019/UI.js | safe | No malicious patterns detected; the code is a legitimate React component for scroll locking with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/es2019/aggresiveCapture.js | safe | No malicious patterns detected; the code is a standard feature-detection snippet for passive event listener support. |
| dist/es2019/handleScroll.js | safe | No malicious patterns detected; the code is a legitimate scroll handling utility with no network, file system, process execution, or obfuscated behavior. |
| dist/es2019/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/medium.js | safe | No malicious patterns detected |
| dist/es2019/pinchAndZoom.js | safe | No malicious patterns detected; the code implements touch gesture detection without network, filesystem, or process manipulation. |
| dist/es2019/sidecar.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es5/Combination.js | safe | No malicious patterns detected |
| dist/es5/SideEffect.js | safe | No malicious patterns detected; the code is a legitimate scroll-locking side-effect component using React hooks and DOM event listeners without any data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/es5/UI.js | safe | No malicious patterns detected; the code is a legitimate React component for scroll locking with standard prop handling and ref usage. |
| dist/es5/aggresiveCapture.js | safe | No malicious patterns detected; the code is a standard passive event listener feature detection utility. |
| dist/es5/handleScroll.js | safe | No malicious patterns detected; the code only implements scroll handling logic using standard DOM APIs. |
Show 5 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/es5/index.js | safe | No malicious patterns detected |
| dist/es5/medium.js | safe | The code is a minimal, non-obfuscated sidecar module initialization that imports a helper library and exports a function, with no malicious patterns detected. |
| dist/es5/pinchAndZoom.js | safe | No malicious patterns detected; only benign touch gesture logic with a minor debug console.log statement. |
| dist/es5/sidecar.js | safe | No malicious patterns detected |
| dist/es5/types.js | safe | No malicious patterns detected |
Frequently asked questions
Is react-remove-scroll safe to use?
Our AI source review of react-remove-scroll@2.7.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does react-remove-scroll contain malware?
No malware was identified in react-remove-scroll@2.7.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was react-remove-scroll checked?
Togoder Security downloaded the published npm package and had an AI model read its 30 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan react-remove-scroll together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react-remove-scroll@2.7.2, cost nothing.