Togoder security

npm package security report

read-cmd-shim@6.0.0 security report

Risky patterns found that deserve a look.

Needs review Version 6.0.0 Files reviewed 1 Size 2.0 KB Scanned

Summary

Togoder Security scanned the npm package read-cmd-shim@6.0.0 on Oct 6, 2026. An AI review of 1 source file produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

regular expression complexity

NPS-A46DEC8E660D

The regex patterns used in extractPathFromPowershell, extractPathFromCmd, and extractPathFromCygwin are relatively simple and not prone to catastrophic backtracking, but they dynamically parse text files. If an attacker controls the shim file content, they could craft malicious input, though the impact is limited to incorrect path extraction, not code execution. This is a low-severity concern.

lib/index.js
low

file system manipulation

NPS-8FEC4FC6FACC

The module reads files from the filesystem (readFileSync and readFile) based on the provided path. It does not restrict paths to a specific directory, so it could be used to read arbitrary files if the calling code passes attacker-controlled paths. However, this is a typical utility behavior for a cmd-shim parser and does not itself indicate malicious intent.

lib/index.js
low

error handling information exposure

NPS-22D9841D781C

Error objects include file paths and error codes, which could leak sensitive path information if errors are logged or displayed to untrusted users. This is a minor information disclosure concern.

lib/index.js

Files reviewed

FileVerdictWhat the reviewer saw
lib/index.js medium The code is a benign utility for reading and parsing cmd-shim files, with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.

Frequently asked questions

Is read-cmd-shim safe to use?

No confirmed malware was found in read-cmd-shim@6.0.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does read-cmd-shim contain malware?

No malware was identified in read-cmd-shim@6.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was read-cmd-shim checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan read-cmd-shim together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in read-cmd-shim@6.0.0, cost nothing.

Related security reports