Summary
Togoder Security scanned the npm package resolve-from@4.0.0 on Oct 6, 2026. An AI review of 1 source file produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Potential path traversal or unintended module loading
NPS-59FF4DD3F0C0
The function resolves module paths relative to a given directory. If an attacker can control the fromDir or moduleId parameters, they could potentially resolve and load modules from arbitrary locations. However, the module does not actually load the resolved module—it only returns the resolved path. This limits the risk.
Dynamic module resolution using internal Node.js API
NPS-50B7714A4F1C
The code uses the private/internal Module._resolveFilename and Module._nodeModulePaths APIs. These are not part of the public API and their behavior can change between Node.js versions. While not inherently malicious, using internal APIs is fragile and can be a red flag if combined with other suspicious behavior. It allows resolving module paths from arbitrary directories, which could be used to load unexpected modules if input is attacker-controlled.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | The code uses internal Node.js module resolution APIs but does not exhibit malicious behavior such as data exfiltration, credential harvesting, or code execution. |
Affected version ranges
None of the 2 scanned versions of resolve-from are flagged high or critical. The latest scanned version, 5.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.0.0 – 5.0.0 | Needs review | 2 | >=4.0.0 <=5.0.0 | |
| 3.0.0 | Not scanned | 1 | 3.0.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of resolve-from
Frequently asked questions
Is resolve-from safe to use?
No confirmed malware was found in resolve-from@4.0.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does resolve-from contain malware?
No malware was identified in resolve-from@4.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was resolve-from checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan resolve-from together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in resolve-from@4.0.0, cost nothing.