# signal-exit@4.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:32.000Z
- Files reviewed: 6
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/signal-exit
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package signal-exit@4.1.0 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Process manipulation / global state override

Finding ID: `NPS-7A9FFDF09753`

File: `dist/mjs/index.js:214`

The code monkey-patches the global Node.js process object by replacing process.emit and process.reallyExit. While this is a known pattern used by the 'signal-exit' library to intercept exit events, it alters core runtime behavior globally and could interfere with other libraries or security controls. This is the primary functional purpose of the package.

### [low] process signal interception

Finding ID: `NPS-123B5D060A67`

File: `dist/cjs/index.js:190`

The module monkey-patches process.emit and process.reallyExit to intercept process exit events, which is expected behavior for a signal handling library (this is the 'signal-exit' package). No exfiltration, credential harvesting, or external network activity is present.

### [low] Global symbol registration

Finding ID: `NPS-8A9D48AFB575`

File: `dist/mjs/index.js:30`

Uses Symbol.for('signal-exit emitter') and defines a non-configurable, non-writable property on globalThis to store a shared Emitter instance. This is a global namespace pollution/state sharing mechanism, though non-configurable means it cannot be easily removed or replaced.

### [low] Signal handler installation

Finding ID: `NPS-79ED90BEC2D3`

File: `dist/mjs/index.js:177`

Registers signal listeners for multiple signals (SIGHUP, SIGINT, SIGTERM, etc.) via process.on and re-sends signals using process.kill(process.pid, sig) to propagate exit behavior. This is the intended functionality but involves killing/re-sending signals to the current process.

## Files reviewed

- `dist/mjs/index.js` (medium): This appears to be the legitimate 'signal-exit' library which hooks process exit/signal events; no malicious data exfiltration, credential harvesting, code execution, or network activity was detected, though it does globally override process.emit and process.reallyExit which is a moderate risk pattern inherent to its purpose.
- `dist/cjs/browser.js` (safe): No malicious patterns detected; the module only exports empty stub functions for load, unload, and onExit.
- `dist/cjs/index.js` (safe): This is the legitimate signal-exit package that intercepts process signals and exit events; no malicious patterns, data exfiltration, or backdoor behavior were detected.
- `dist/cjs/signals.js` (safe): No malicious patterns detected; the file is a benign signal list used by an exit-handler utility.
- `dist/mjs/browser.js` (safe): No malicious patterns detected
- `dist/mjs/signals.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
