# regexp.prototype.flags@1.5.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:18.000Z
- Files reviewed: 5
- Findings: 3 medium severity findings
- Report: https://security.togoder.click/npm/regexp.prototype.flags
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package regexp.prototype.flags@1.5.4 on Oct 6, 2026. An AI review of 5 source files produced 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Indirect code execution via module import

Finding ID: `NPS-BE5CBBBF7046`

File: `auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-D6116D641FE2`

File: `auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-109653960593`

File: `auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

## Files reviewed

- `auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `implementation.js` (safe): No malicious patterns detected
- `index.js` (safe): No malicious patterns detected; the code is a standard polyfill wrapper for Function.prototype.bind and uses only legitimate dependencies.
- `polyfill.js` (safe): Cleared by Jev triage; no further analysis needed
- `shim.js` (safe): No malicious patterns detected; the code is a standard ES5 RegExp.prototype.flags polyfill shim.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
