Togoder security

npm package security report

slow-redact npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.3.2 Files reviewed 5 Size 20.4 KB Scanned

Summary

Togoder Security scanned the npm package slow-redact@0.3.2 on Oct 4, 2026. An AI review of 5 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Install/build-time execution surface

NPS-BA28AF6ECEC4

This is a lifecycle/build helper script. When wired into npm scripts (e.g., prepublish, preinstall, version), it executes automatically and mutates package.json based on attacker-influenced argv input without validating the version string against a semver regex or allowlist. Unsanitized input is written directly into package.json, which can enable supply-chain version-spoofing or injection if the file is later published.

scripts/sync-version.mjs:9
medium

File system manipulation

NPS-1151842655DE

The script reads and writes package.json. While reading is expected, the write operation uses a hardcoded relative path './package.json' instead of the resolved absolute path 'packageJsonPath' used for reading. This causes the write to target a potentially different file depending on the current working directory, which is inconsistent and could be exploited if the script is invoked from an unexpected directory (e.g., overwriting an unintended package.json outside the intended scope).

scripts/sync-version.mjs:16
low

Test credentials

NPS-E37F375744C9

Hard-coded test secrets (passwords, cookies, API keys) are present in benchmark fixtures. These are dummy values for performance testing and are not harvested or exfiltrated.

benchmarks/basic.js:8

Files reviewed

FileVerdictWhat the reviewer saw
scripts/sync-version.mjs medium No overtly malicious behavior (no network calls, credential access, obfuscation, or process spawning), but the script performs unvalidated filesystem writes to a relative path based on user-supplied input, posing a supply-chain tampering risk.
benchmarks/basic.js safe The file is a benchmark script for redaction libraries and contains no malicious behavior such as data exfiltration, credential harvesting, obfuscation, or process execution.
eslint.config.js safe No malicious patterns detected
index.js safe No malicious patterns detected
index.test-d.ts safe Cleared by Jev triage; no further analysis needed

Scanned versions of slow-redact

VersionVerdictFilesScanned
0.3.2 Needs review 5 Oct 4, 2026

Frequently asked questions

Is slow-redact safe to use?

No confirmed malware was found in slow-redact@0.3.2, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does slow-redact contain malware?

No malware was identified in slow-redact@0.3.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was slow-redact checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan slow-redact together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in slow-redact@0.3.2, cost nothing.

Related security reports