Summary
Togoder Security scanned the npm package sharp@0.35.5 on Oct 6, 2026. An AI review of 27 source files produced 7 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 16
Spawn with shell enabled
NPS-7C0C2D0D0DBC
spawnSyncOptions sets shell: true, and spawnSync is used with string commands (e.g. 'sysctl sysctl.proc_translated', 'pkg-config --modversion vips-cpp', and the node-gyp rebuild command). Using shell: true with string commands can enable shell injection if any component of the command is influenced by attacker-controlled input. In this file the strings appear static, but buildPlatformArch() can incorporate environment variables (npm_config_platform, npm_config_arch, npm_config_libc) that are used in dynamic require paths rather than in the shell commands.
Shell command execution
NPS-3F07E3F91F55
Multiple spawnSync calls use { shell: true }, which invokes commands through the system shell. The commands themselves are hardcoded (not directly attacker-controlled), but shell: true broadens the attack surface if any interpolated value were ever influenced. This is a common pattern for build tooling but deserves scrutiny.
Dynamic module loading with computed paths
NPS-B4A409E8C328
require() is called with template-literal paths built from buildPlatformArch(), which itself reads npm_config_arch / npm_config_platform / npm_config_libc environment variables. An attacker with control over the npm environment (e.g. via env vars) could influence which module is loaded, though the require is restricted to @img/sharp-* packages.
Dynamic module loading with computed paths
NPS-945D956E9DF8
The code uses require() with dynamically constructed paths based on runtime platform and package version (e.g., ../src/build/Release/sharp-${runtimePlatform}-${version}.node). While these are derived from internal package metadata, the pattern of dynamic native module loading could be exploited if the runtime environment is compromised or if the package.json version is manipulated to load an arbitrary .node file. This is a common technique in legitimate native addon packages but warrants attention as it loads executable native code at import time.
Native binary loading at import time
NPS-B5B5A69EBC95
The module loads platform-specific native .node binaries (via require) immediately upon import. Native modules execute arbitrary machine code with full process privileges. While this is the intended functionality of sharp, the automatic loading of prebuilt binaries from multiple sources (local build, @img/ scoped packages, wasm fallback) means that a compromised or malicious optional dependency could execute code. This is standard for native Node.js addons but is a high-impact vector if any dependency is untrusted.
Install-time code execution
NPS-5D2F67B180DB
This file (install/build.js) is executed during the npm install lifecycle (likely via a preinstall/install script). It performs top-level logic including requiring external modules and invoking spawnRebuild(), which may run build tools or shell commands. Any code executed at install time is a potential vector for supply-chain attacks; without seeing spawnRebuild's implementation, it cannot be verified as safe.
Dynamic module loading and process spawning
NPS-B6D4AF2B6079
The script uses require() to dynamically load 'node-addon-api' and 'node-gyp' at install/build time. While these are expected dependencies for native module compilation, the use of require() on external modules within a build script is a common pattern in malicious packages (e.g., to load a payload). Additionally, spawnRebuild() (imported from ../dist/libvips.cjs) is called without inspecting its implementation; it could spawn arbitrary processes or execute shell commands, which is a high-risk pattern if the referenced module is compromised or tampered with.
No credential or sensitive file access
NPS-291A6EAFA3E6
The code does not read .npmrc, .ssh, .aws, browser profiles, wallet files, or other credential stores. It only reads package.json and environment variables related to build configuration.
No network exfiltration
NPS-76F1E4530139
No network requests (http, https, fetch, net, dns, etc.) are present in this file. The only external interaction is via local command execution and module resolution.
Environment variable influence on platform/architecture detection
NPS-B05DC9F2DC55
buildPlatformArch() reads npm_config_arch, npm_config_platform, and npm_config_libc from process.env and uses them to construct package names passed to require(). If an attacker can control these environment variables, they may influence which module is loaded. This is a potential dynamic module loading vector, though the values are constrained to platform/arch/libc-like strings.
Dynamic require with computed input
NPS-855DE50924D5
buildSharpLibvipsIncludeDir, buildSharpLibvipsCPlusPlusDir, and buildSharpLibvipsLibDir call require() with template-literal package names that depend on buildPlatformArch(). While this is legitimate for multi-platform binary packages, computed require paths are a general code-smell and could be abused if environment variables or other inputs are attacker-controlled.
Process spawning at module load / build time
NPS-211B480EBC00
The module invokes spawnSync for sysctl, pkg-config, brew, and node-gyp. These are legitimate build/install helpers for the sharp image library, but they execute external commands during installation or import. No obvious data exfiltration, credential harvesting, or reverse-shell behavior is present.
Environment variable harvesting
NPS-7B49B616E4B9
Reads npm_config_arch, npm_config_platform, npm_config_libc, CC, SHARP_IGNORE_GLOBAL_LIBVIPS, SHARP_FORCE_GLOBAL_LIBVIPS, npm_package_config_libvips, PKG_CONFIG_PATH. These are legitimate for a native-addon build helper, but env access is a pattern to note. No credentials (.npmrc, SSH, AWS, etc.) are read.
Process spawning for system introspection
NPS-A6DBCE25BA22
Spawns sysctl, pkg-config, and brew to detect platform/libvips configuration. These are expected for a libvips binding and the arguments are static. The 'brew' and 'pkg-config' invocations do not use shell: true.
Top-level code execution at import time
NPS-E7DC2280B921
Module executes top-level logic (semver.coerce on pkg.config.libvips) but does not spawn processes, perform network I/O, or modify the filesystem at import. spawnRebuild is only invoked externally.
Potential information disclosure in error messages
NPS-1E8EC96982E2
Error handling collects and includes error messages/codes in a help message thrown to the user. In Linux environments, it conditionally reads package metadata from @img/sharp-libvips-* and includes libc family/version. This does not exfiltrate data externally, but could expose environment details in logs. No network transmission occurs.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/libvips.cjs | medium | This is the legitimate sharp/libvips platform-detection and build helper code; it spawns local build tools with shell enabled and uses environment-influenced dynamic requires, which are worth noting but do not constitute malicious behavior. |
| dist/libvips.mjs | medium | No malicious behavior detected; this is a legitimate native-addon build helper (sharp/libvips) with expected process spawning and env var reads, but uses shell:true and computed require paths that warrant caution. |
| dist/sharp.mjs | medium | The code is a legitimate native module loader for the sharp image processing library, but it dynamically requires platform-specific native binaries at import time, which is a common but high-impact pattern if dependencies are compromised. |
| install/build.js | medium | The build script appears to be a legitimate native module compilation helper for sharp/libvips, but it dynamically requires external modules and calls an uninspected spawnRebuild function at install time, warranting a warning rather than a clean 'safe' verdict. |
| dist/channel.cjs | safe | This is a standard sharp library channel operation module with no malicious patterns detected. |
| dist/channel.mjs | safe | No malicious patterns detected; this is a legitimate sharp image processing module with standard channel manipulation functions. |
| dist/colour.cjs | safe | No malicious patterns detected; the file contains legitimate Sharp image library colourspace handling code with no network, process, filesystem, or dynamic code execution activity. |
| dist/colour.mjs | safe | No malicious patterns detected; the code is a legitimate Sharp image processing module handling colour options and colourspaces. |
| dist/composite.cjs | safe | No malicious patterns detected |
| dist/composite.mjs | safe | No malicious patterns detected; the code is a standard image compositing API for the sharp library with proper input validation and no dynamic code execution, network access, or filesystem manipulation. |
| dist/constructor.cjs | safe | No malicious patterns detected; the file is a legitimate Sharp image processing library constructor with standard option initialization and stream setup. |
| dist/constructor.mjs | safe | No malicious patterns detected; this is the legitimate sharp npm package constructor with standard image processing options and no data exfiltration, credential harvesting, or dynamic code execution. |
| dist/index.cjs | safe | No malicious patterns detected |
| dist/index.mjs | safe | No malicious patterns detected; the file is a standard entry point for the Sharp image processing library that imports and applies prototype extensions from local modules. |
| dist/input.cjs | safe | This is a legitimate input options handling module for the sharp image processing library, containing only parameter validation and option normalization logic with no malicious patterns. |
| dist/input.mjs | safe | No malicious patterns detected; the file contains standard input option validation and processing logic for the sharp image library. |
| dist/is.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/is.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/operation.cjs | safe | No malicious patterns detected |
| dist/operation.mjs | safe | No malicious patterns detected; this is a legitimate image processing API definition module from the sharp library with only parameter validation and option setting. |
| dist/output.cjs | safe | This is the legitimate sharp image processing library output module; no malicious patterns, exfiltration, obfuscation, dynamic code execution, or suspicious network/process activity detected. |
| dist/output.mjs | safe | No malicious patterns detected; the code is the legitimate output-formatting module of the well-known sharp image processing library and only performs local image encoding with no network, credential, obfuscation, or process-spawning behavior. |
| dist/resize.cjs | safe | No malicious patterns detected; the file is a standard sharp image-processing module containing only parameter validation and option mapping with no data exfiltration, credential harvesting, obfuscation, network calls, or process spawning. |
| dist/resize.mjs | safe | No malicious patterns detected in this image resize utility module from the sharp library; it contains only parameter validation, option mapping, and prototype decoration with no network, filesystem, process, or dynamic code execution behavior. |
| dist/sharp.cjs | safe | No malicious patterns detected; the file is the standard sharp module loader that dynamically requires platform-specific native bindings and provides installation troubleshooting. |
Show 2 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/utility.cjs | safe | No malicious patterns detected |
| dist/utility.mjs | safe | No malicious patterns detected |
Scanned versions of sharp
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 0.35.5 | Needs review | 27 | Oct 6, 2026 |
Frequently asked questions
Is sharp safe to use?
No confirmed malware was found in sharp@0.35.5, but the review flagged 7 medium, 9 low severity findings for risky patterns worth checking before you rely on it.
Does sharp contain malware?
No malware was identified in sharp@0.35.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was sharp checked?
Togoder Security downloaded the published npm package and had an AI model read its 27 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan sharp together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in sharp@0.35.5, cost nothing.