Summary
Togoder Security scanned the npm package signal-exit@4.1.0 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Process manipulation / global state override
NPS-7A9FFDF09753
The code monkey-patches the global Node.js process object by replacing process.emit and process.reallyExit. While this is a known pattern used by the 'signal-exit' library to intercept exit events, it alters core runtime behavior globally and could interfere with other libraries or security controls. This is the primary functional purpose of the package.
process signal interception
NPS-123B5D060A67
The module monkey-patches process.emit and process.reallyExit to intercept process exit events, which is expected behavior for a signal handling library (this is the 'signal-exit' package). No exfiltration, credential harvesting, or external network activity is present.
Global symbol registration
NPS-8A9D48AFB575
Uses Symbol.for('signal-exit emitter') and defines a non-configurable, non-writable property on globalThis to store a shared Emitter instance. This is a global namespace pollution/state sharing mechanism, though non-configurable means it cannot be easily removed or replaced.
Signal handler installation
NPS-79ED90BEC2D3
Registers signal listeners for multiple signals (SIGHUP, SIGINT, SIGTERM, etc.) via process.on and re-sends signals using process.kill(process.pid, sig) to propagate exit behavior. This is the intended functionality but involves killing/re-sending signals to the current process.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/mjs/index.js | medium | This appears to be the legitimate 'signal-exit' library which hooks process exit/signal events; no malicious data exfiltration, credential harvesting, code execution, or network activity was detected, though it does globally override process.emit and process.reallyExit which is a moderate risk pattern inherent to its purpose. |
| dist/cjs/browser.js | safe | No malicious patterns detected; the module only exports empty stub functions for load, unload, and onExit. |
| dist/cjs/index.js | safe | This is the legitimate signal-exit package that intercepts process signals and exit events; no malicious patterns, data exfiltration, or backdoor behavior were detected. |
| dist/cjs/signals.js | safe | No malicious patterns detected; the file is a benign signal list used by an exit-handler utility. |
| dist/mjs/browser.js | safe | No malicious patterns detected |
| dist/mjs/signals.js | safe | No malicious patterns detected |
Frequently asked questions
Is signal-exit safe to use?
No confirmed malware was found in signal-exit@4.1.0, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does signal-exit contain malware?
No malware was identified in signal-exit@4.1.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was signal-exit checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan signal-exit together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in signal-exit@4.1.0, cost nothing.