# sharp@0.35.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:31.000Z
- Files reviewed: 27
- Findings: 7 medium, 9 low severity findings
- Report: https://security.togoder.click/npm/sharp
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package sharp@0.35.5 on Oct 6, 2026. An AI review of 27 source files produced 7 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Spawn with shell enabled

Finding ID: `NPS-7C0C2D0D0DBC`

File: `dist/libvips.cjs:27`

spawnSyncOptions sets shell: true, and spawnSync is used with string commands (e.g. 'sysctl sysctl.proc_translated', 'pkg-config --modversion vips-cpp', and the node-gyp rebuild command). Using shell: true with string commands can enable shell injection if any component of the command is influenced by attacker-controlled input. In this file the strings appear static, but buildPlatformArch() can incorporate environment variables (npm_config_platform, npm_config_arch, npm_config_libc) that are used in dynamic require paths rather than in the shell commands.

### [medium] Shell command execution

Finding ID: `NPS-3F07E3F91F55`

File: `dist/libvips.mjs`

Multiple spawnSync calls use { shell: true }, which invokes commands through the system shell. The commands themselves are hardcoded (not directly attacker-controlled), but shell: true broadens the attack surface if any interpolated value were ever influenced. This is a common pattern for build tooling but deserves scrutiny.

### [medium] Dynamic module loading with computed paths

Finding ID: `NPS-B4A409E8C328`

File: `dist/libvips.mjs`

require() is called with template-literal paths built from buildPlatformArch(), which itself reads npm_config_arch / npm_config_platform / npm_config_libc environment variables. An attacker with control over the npm environment (e.g. via env vars) could influence which module is loaded, though the require is restricted to @img/sharp-* packages.

### [medium] Dynamic module loading with computed paths

Finding ID: `NPS-945D956E9DF8`

File: `dist/sharp.mjs:20`

The code uses require() with dynamically constructed paths based on runtime platform and package version (e.g., `../src/build/Release/sharp-${runtimePlatform}-${version}.node`). While these are derived from internal package metadata, the pattern of dynamic native module loading could be exploited if the runtime environment is compromised or if the package.json version is manipulated to load an arbitrary .node file. This is a common technique in legitimate native addon packages but warrants attention as it loads executable native code at import time.

### [medium] Native binary loading at import time

Finding ID: `NPS-B5B5A69EBC95`

File: `dist/sharp.mjs:20`

The module loads platform-specific native .node binaries (via require) immediately upon import. Native modules execute arbitrary machine code with full process privileges. While this is the intended functionality of sharp, the automatic loading of prebuilt binaries from multiple sources (local build, @img/ scoped packages, wasm fallback) means that a compromised or malicious optional dependency could execute code. This is standard for native Node.js addons but is a high-impact vector if any dependency is untrusted.

### [medium] Install-time code execution

Finding ID: `NPS-5D2F67B180DB`

File: `install/build.js:1`

This file (install/build.js) is executed during the npm install lifecycle (likely via a preinstall/install script). It performs top-level logic including requiring external modules and invoking spawnRebuild(), which may run build tools or shell commands. Any code executed at install time is a potential vector for supply-chain attacks; without seeing spawnRebuild's implementation, it cannot be verified as safe.

### [medium] Dynamic module loading and process spawning

Finding ID: `NPS-B6D4AF2B6079`

File: `install/build.js:17`

The script uses require() to dynamically load 'node-addon-api' and 'node-gyp' at install/build time. While these are expected dependencies for native module compilation, the use of require() on external modules within a build script is a common pattern in malicious packages (e.g., to load a payload). Additionally, spawnRebuild() (imported from ../dist/libvips.cjs) is called without inspecting its implementation; it could spawn arbitrary processes or execute shell commands, which is a high-risk pattern if the referenced module is compromised or tampered with.

### [low] No credential or sensitive file access

Finding ID: `NPS-291A6EAFA3E6`

File: `dist/libvips.cjs`

The code does not read .npmrc, .ssh, .aws, browser profiles, wallet files, or other credential stores. It only reads package.json and environment variables related to build configuration.

### [low] No network exfiltration

Finding ID: `NPS-76F1E4530139`

File: `dist/libvips.cjs`

No network requests (http, https, fetch, net, dns, etc.) are present in this file. The only external interaction is via local command execution and module resolution.

### [low] Environment variable influence on platform/architecture detection

Finding ID: `NPS-B05DC9F2DC55`

File: `dist/libvips.cjs:49`

buildPlatformArch() reads npm_config_arch, npm_config_platform, and npm_config_libc from process.env and uses them to construct package names passed to require(). If an attacker can control these environment variables, they may influence which module is loaded. This is a potential dynamic module loading vector, though the values are constrained to platform/arch/libc-like strings.

### [low] Dynamic require with computed input

Finding ID: `NPS-855DE50924D5`

File: `dist/libvips.cjs:59`

buildSharpLibvipsIncludeDir, buildSharpLibvipsCPlusPlusDir, and buildSharpLibvipsLibDir call require() with template-literal package names that depend on buildPlatformArch(). While this is legitimate for multi-platform binary packages, computed require paths are a general code-smell and could be abused if environment variables or other inputs are attacker-controlled.

### [low] Process spawning at module load / build time

Finding ID: `NPS-211B480EBC00`

File: `dist/libvips.cjs:81`

The module invokes spawnSync for sysctl, pkg-config, brew, and node-gyp. These are legitimate build/install helpers for the sharp image library, but they execute external commands during installation or import. No obvious data exfiltration, credential harvesting, or reverse-shell behavior is present.

### [low] Environment variable harvesting

Finding ID: `NPS-7B49B616E4B9`

File: `dist/libvips.mjs`

Reads npm_config_arch, npm_config_platform, npm_config_libc, CC, SHARP_IGNORE_GLOBAL_LIBVIPS, SHARP_FORCE_GLOBAL_LIBVIPS, npm_package_config_libvips, PKG_CONFIG_PATH. These are legitimate for a native-addon build helper, but env access is a pattern to note. No credentials (.npmrc, SSH, AWS, etc.) are read.

### [low] Process spawning for system introspection

Finding ID: `NPS-A6DBCE25BA22`

File: `dist/libvips.mjs`

Spawns sysctl, pkg-config, and brew to detect platform/libvips configuration. These are expected for a libvips binding and the arguments are static. The 'brew' and 'pkg-config' invocations do not use shell: true.

### [low] Top-level code execution at import time

Finding ID: `NPS-E7DC2280B921`

File: `dist/libvips.mjs`

Module executes top-level logic (semver.coerce on pkg.config.libvips) but does not spawn processes, perform network I/O, or modify the filesystem at import. spawnRebuild is only invoked externally.

### [low] Potential information disclosure in error messages

Finding ID: `NPS-1E8EC96982E2`

File: `dist/sharp.mjs:120`

Error handling collects and includes error messages/codes in a help message thrown to the user. In Linux environments, it conditionally reads package metadata from @img/sharp-libvips-* and includes libc family/version. This does not exfiltrate data externally, but could expose environment details in logs. No network transmission occurs.

## Files reviewed

- `dist/libvips.cjs` (medium): This is the legitimate sharp/libvips platform-detection and build helper code; it spawns local build tools with shell enabled and uses environment-influenced dynamic requires, which are worth noting but do not constitute malicious behavior.
- `dist/libvips.mjs` (medium): No malicious behavior detected; this is a legitimate native-addon build helper (sharp/libvips) with expected process spawning and env var reads, but uses shell:true and computed require paths that warrant caution.
- `dist/sharp.mjs` (medium): The code is a legitimate native module loader for the sharp image processing library, but it dynamically requires platform-specific native binaries at import time, which is a common but high-impact pattern if dependencies are compromised.
- `install/build.js` (medium): The build script appears to be a legitimate native module compilation helper for sharp/libvips, but it dynamically requires external modules and calls an uninspected spawnRebuild function at install time, warranting a warning rather than a clean 'safe' verdict.
- `dist/channel.cjs` (safe): This is a standard sharp library channel operation module with no malicious patterns detected.
- `dist/channel.mjs` (safe): No malicious patterns detected; this is a legitimate sharp image processing module with standard channel manipulation functions.
- `dist/colour.cjs` (safe): No malicious patterns detected; the file contains legitimate Sharp image library colourspace handling code with no network, process, filesystem, or dynamic code execution activity.
- `dist/colour.mjs` (safe): No malicious patterns detected; the code is a legitimate Sharp image processing module handling colour options and colourspaces.
- `dist/composite.cjs` (safe): No malicious patterns detected
- `dist/composite.mjs` (safe): No malicious patterns detected; the code is a standard image compositing API for the sharp library with proper input validation and no dynamic code execution, network access, or filesystem manipulation.
- `dist/constructor.cjs` (safe): No malicious patterns detected; the file is a legitimate Sharp image processing library constructor with standard option initialization and stream setup.
- `dist/constructor.mjs` (safe): No malicious patterns detected; this is the legitimate sharp npm package constructor with standard image processing options and no data exfiltration, credential harvesting, or dynamic code execution.
- `dist/index.cjs` (safe): No malicious patterns detected
- `dist/index.mjs` (safe): No malicious patterns detected; the file is a standard entry point for the Sharp image processing library that imports and applies prototype extensions from local modules.
- `dist/input.cjs` (safe): This is a legitimate input options handling module for the sharp image processing library, containing only parameter validation and option normalization logic with no malicious patterns.
- `dist/input.mjs` (safe): No malicious patterns detected; the file contains standard input option validation and processing logic for the sharp image library.
- `dist/is.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/is.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/operation.cjs` (safe): No malicious patterns detected
- `dist/operation.mjs` (safe): No malicious patterns detected; this is a legitimate image processing API definition module from the sharp library with only parameter validation and option setting.
- `dist/output.cjs` (safe): This is the legitimate sharp image processing library output module; no malicious patterns, exfiltration, obfuscation, dynamic code execution, or suspicious network/process activity detected.
- `dist/output.mjs` (safe): No malicious patterns detected; the code is the legitimate output-formatting module of the well-known sharp image processing library and only performs local image encoding with no network, credential, obfuscation, or process-spawning behavior.
- `dist/resize.cjs` (safe): No malicious patterns detected; the file is a standard sharp image-processing module containing only parameter validation and option mapping with no data exfiltration, credential harvesting, obfuscation, network calls, or process spawning.
- `dist/resize.mjs` (safe): No malicious patterns detected in this image resize utility module from the sharp library; it contains only parameter validation, option mapping, and prototype decoration with no network, filesystem, process, or dynamic code execution behavior.
- `dist/sharp.cjs` (safe): No malicious patterns detected; the file is the standard sharp module loader that dynamically requires platform-specific native bindings and provides installation troubleshooting.
- `dist/utility.cjs` (safe): No malicious patterns detected
- `dist/utility.mjs` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
