Summary
Togoder Security scanned the npm package scheduler@0.28.0 on Oct 6, 2026. An AI review of 12 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cjs/scheduler-unstable_mock.development.js | safe | No malicious patterns detected; this is the legitimate React scheduler mock implementation with no network, filesystem, process, or obfuscated code activity. |
| cjs/scheduler-unstable_mock.production.js | safe | No malicious patterns detected; this is the legitimate React scheduler unstable mock production build with no network, filesystem, process, or dynamic execution activity. |
| cjs/scheduler-unstable_post_task.development.js | safe | This is the legitimate React Scheduler package using the browser postTask API; no malicious patterns detected. |
| cjs/scheduler-unstable_post_task.production.js | safe | No malicious patterns detected; the file is a legitimate React scheduler implementation that uses standard browser APIs and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| cjs/scheduler.development.js | safe | This is the legitimate React scheduler development build from Meta with no malicious patterns detected; it only contains standard task scheduling logic, timer/heap management, and React DevTools hook integration. |
| cjs/scheduler.native.development.js | safe | No malicious patterns detected |
| cjs/scheduler.native.production.js | safe | This is the official React scheduler production build for React Native, containing only legitimate task scheduling logic with no malicious patterns. |
| cjs/scheduler.production.js | safe | No malicious patterns detected; this is the standard React Scheduler production build with expected internal task scheduling logic and no suspicious behavior. |
| index.js | safe | No malicious patterns detected |
| index.native.js | safe | No malicious patterns detected; the file is a standard React Scheduler environment-based module loader. |
| unstable_mock.js | safe | Standard React Scheduler mock entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected. |
| unstable_post_task.js | safe | No malicious patterns detected |
Frequently asked questions
Is scheduler safe to use?
Our AI source review of scheduler@0.28.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does scheduler contain malware?
No malware was identified in scheduler@0.28.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was scheduler checked?
Togoder Security downloaded the published npm package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan scheduler together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in scheduler@0.28.0, cost nothing.