Togoder security

npm package security report

safer-buffer@2.1.2 security report

Risky patterns found that deserve a look.

Needs review Version 2.1.2 Files reviewed 3 Size 18.9 KB Scanned

Summary

Togoder Security scanned the npm package safer-buffer@2.1.2 on Oct 4, 2026. An AI review of 3 source files produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
2
low

Findings 5

medium

unsafe buffer allocation

NPS-88F499E3D69C

This module intentionally exposes Node.js 'unsafe' Buffer allocation methods (allocUnsafe, allocUnsafeSlow, and deprecated legacy Buffer constructor). Uninitialized buffers can leak sensitive process memory (previous allocations containing secrets, tokens, or passwords) to callers. While this is not malicious per se, it is a deliberate re-exposure of dangerous APIs and could facilitate information disclosure if consumers misuse it.

dangerous.js:34
medium

deprecated unsafe constructor usage

NPS-60029AD700F7

The fallback implementation of allocUnsafe calls the deprecated Buffer(size) constructor, which allocates uninitialized memory. This reintroduces a known-unsafe API pattern that Node.js has deprecated specifically for security reasons.

dangerous.js:41
medium

potential memory disclosure via SlowBuffer

NPS-49218F2F5E81

Dangereous.allocUnsafeSlow falls back to buffer.SlowBuffer(size), which also returns uninitialized memory. Combined with the re-exported unsafe APIs, this module is a known package ('safer-buffer' companion) whose entire purpose is to expose unsafe Buffer methods for callers who explicitly opt in; consumers should be aware this bypasses Node's buffer initialization protections.

dangerous.js:51
low

Deprecated API Usage

NPS-2C3819A16B2F

The code uses Buffer() constructor without 'new' in the 'alloc' and 'from' fallback functions, which is deprecated and can lead to security vulnerabilities (uninitialized memory). However, the code includes safeguards: 'alloc' fills the buffer with zeros if no fill is provided, and 'from' explicitly rejects numbers and non-array-like objects. This is a deliberate attempt to provide a safer alternative to the deprecated Buffer API.

safer.js:29
low

Dynamic Code Execution

NPS-4E10D084655F

The use of 'process.binding' is a Node.js internal API that can access native bindings. While not inherently malicious, it is a low-level, non-public API and could be a concern if misused. However, here it is used to retrieve 'kStringMaxLength' and is wrapped in a try-catch to handle unsupported environments.

safer.js:72

Files reviewed

FileVerdictWhat the reviewer saw
dangerous.js medium No malicious exfiltration, credential harvesting, code execution, or backdoor patterns found, but the module deliberately re-exposes unsafe Node.js Buffer APIs that can leak uninitialized process memory to callers.
safer.js safe The code appears to be a safety wrapper for the Node.js Buffer API, implementing safeguards against deprecated and unsafe behaviors, with no malicious patterns detected.
tests.js safe This is a test file for a Buffer polyfill package that only tests API behavior; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were found.

Frequently asked questions

Is safer-buffer safe to use?

No confirmed malware was found in safer-buffer@2.1.2, but the review flagged 3 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does safer-buffer contain malware?

No malware was identified in safer-buffer@2.1.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was safer-buffer checked?

Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan safer-buffer together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in safer-buffer@2.1.2, cost nothing.

Related security reports