# real-require@0.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:40:08.000Z
- Files reviewed: 1
- Findings: 3 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/real-require@0.1.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package real-require@0.1.0 on Oct 4, 2026. An AI review of 1 source file produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-8B271C62E3FF`

File: `src/index.js:4`

Uses new Function('modulePath', 'return import(modulePath)') to construct a dynamic import at runtime. While this is a known pattern to bypass bundlers like webpack, it enables arbitrary module loading if modulePath is attacker-controlled.

### [medium] Dynamic module loading

Finding ID: `NPS-84FA83E8285C`

File: `src/index.js:4`

realImport accepts an arbitrary modulePath and dynamically imports it. If callers pass untrusted input, this could lead to loading of malicious modules. The use of computed module paths bypasses static analysis and bundler safeguards.

### [medium] Dynamic module loading

Finding ID: `NPS-7C5095159EA0`

File: `src/index.js:11`

realRequire falls back to global require(modulePath) with an arbitrary caller-supplied path, again allowing dynamic loading of any module reachable by the Node resolver.

### [low] Bundler/security boundary bypass

Finding ID: `NPS-CE44DB92C896`

File: `src/index.js`

References __non_webpack__require__ and constructs a Function-based import specifically to escape webpack's static analysis. This pattern is legitimate for some libraries but is also commonly abused to hide module-loading behavior from security tooling.

## Files reviewed

- `src/index.js` (medium): The file is a small utility exposing dynamic import/require wrappers; no exfiltration, process spawning, or credential harvesting is present, but the new Function-based dynamic import and computed module loading warrant caution if callers pass untrusted paths.

## Version ranges

None of the 2 scanned versions of real-require are flagged high or critical. The latest scanned version, 0.2.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 0.1.0 – 0.2.0 (`>=0.1.0 <=0.2.0`): medium (Dynamic code execution +1 more)

## Scanned versions

- [0.2.0](https://security.togoder.click/npm/real-require@0.2.0): medium, 2026-10-04T21:17:54.000Z
- [0.1.0](https://security.togoder.click/npm/real-require@0.1.0): medium, 2026-10-04T16:40:08.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
