Summary
Togoder Security scanned the npm package safer-buffer@2.1.2 on Oct 4, 2026. An AI review of 3 source files produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
unsafe buffer allocation
NPS-88F499E3D69C
This module intentionally exposes Node.js 'unsafe' Buffer allocation methods (allocUnsafe, allocUnsafeSlow, and deprecated legacy Buffer constructor). Uninitialized buffers can leak sensitive process memory (previous allocations containing secrets, tokens, or passwords) to callers. While this is not malicious per se, it is a deliberate re-exposure of dangerous APIs and could facilitate information disclosure if consumers misuse it.
deprecated unsafe constructor usage
NPS-60029AD700F7
The fallback implementation of allocUnsafe calls the deprecated Buffer(size) constructor, which allocates uninitialized memory. This reintroduces a known-unsafe API pattern that Node.js has deprecated specifically for security reasons.
potential memory disclosure via SlowBuffer
NPS-49218F2F5E81
Dangereous.allocUnsafeSlow falls back to buffer.SlowBuffer(size), which also returns uninitialized memory. Combined with the re-exported unsafe APIs, this module is a known package ('safer-buffer' companion) whose entire purpose is to expose unsafe Buffer methods for callers who explicitly opt in; consumers should be aware this bypasses Node's buffer initialization protections.
Deprecated API Usage
NPS-2C3819A16B2F
The code uses Buffer() constructor without 'new' in the 'alloc' and 'from' fallback functions, which is deprecated and can lead to security vulnerabilities (uninitialized memory). However, the code includes safeguards: 'alloc' fills the buffer with zeros if no fill is provided, and 'from' explicitly rejects numbers and non-array-like objects. This is a deliberate attempt to provide a safer alternative to the deprecated Buffer API.
Dynamic Code Execution
NPS-4E10D084655F
The use of 'process.binding' is a Node.js internal API that can access native bindings. While not inherently malicious, it is a low-level, non-public API and could be a concern if misused. However, here it is used to retrieve 'kStringMaxLength' and is wrapped in a try-catch to handle unsupported environments.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dangerous.js | medium | No malicious exfiltration, credential harvesting, code execution, or backdoor patterns found, but the module deliberately re-exposes unsafe Node.js Buffer APIs that can leak uninitialized process memory to callers. |
| safer.js | safe | The code appears to be a safety wrapper for the Node.js Buffer API, implementing safeguards against deprecated and unsafe behaviors, with no malicious patterns detected. |
| tests.js | safe | This is a test file for a Buffer polyfill package that only tests API behavior; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were found. |
Scanned versions of safer-buffer
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.1.2 | Needs review | 3 | Oct 4, 2026 |
Frequently asked questions
Is safer-buffer safe to use?
No confirmed malware was found in safer-buffer@2.1.2, but the review flagged 3 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does safer-buffer contain malware?
No malware was identified in safer-buffer@2.1.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was safer-buffer checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan safer-buffer together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in safer-buffer@2.1.2, cost nothing.