Summary
Togoder Security scanned the npm package slow-redact@0.3.2 on Oct 4, 2026. An AI review of 5 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Install/build-time execution surface
NPS-BA28AF6ECEC4
This is a lifecycle/build helper script. When wired into npm scripts (e.g., prepublish, preinstall, version), it executes automatically and mutates package.json based on attacker-influenced argv input without validating the version string against a semver regex or allowlist. Unsanitized input is written directly into package.json, which can enable supply-chain version-spoofing or injection if the file is later published.
File system manipulation
NPS-1151842655DE
The script reads and writes package.json. While reading is expected, the write operation uses a hardcoded relative path './package.json' instead of the resolved absolute path 'packageJsonPath' used for reading. This causes the write to target a potentially different file depending on the current working directory, which is inconsistent and could be exploited if the script is invoked from an unexpected directory (e.g., overwriting an unintended package.json outside the intended scope).
Test credentials
NPS-E37F375744C9
Hard-coded test secrets (passwords, cookies, API keys) are present in benchmark fixtures. These are dummy values for performance testing and are not harvested or exfiltrated.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| scripts/sync-version.mjs | medium | No overtly malicious behavior (no network calls, credential access, obfuscation, or process spawning), but the script performs unvalidated filesystem writes to a relative path based on user-supplied input, posing a supply-chain tampering risk. |
| benchmarks/basic.js | safe | The file is a benchmark script for redaction libraries and contains no malicious behavior such as data exfiltration, credential harvesting, obfuscation, or process execution. |
| eslint.config.js | safe | No malicious patterns detected |
| index.js | safe | No malicious patterns detected |
| index.test-d.ts | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of slow-redact
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 0.3.2 | Needs review | 5 | Oct 4, 2026 |
Frequently asked questions
Is slow-redact safe to use?
No confirmed malware was found in slow-redact@0.3.2, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does slow-redact contain malware?
No malware was identified in slow-redact@0.3.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was slow-redact checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan slow-redact together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in slow-redact@0.3.2, cost nothing.