# string.prototype.matchall@4.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:30.000Z
- Files reviewed: 7
- Findings: 3 medium severity findings
- Report: https://security.togoder.click/npm/string.prototype.matchall
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package string.prototype.matchall@4.1.0 on Oct 6, 2026. An AI review of 7 source files produced 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Indirect code execution via module import

Finding ID: `NPS-887FA03EFC32`

File: `auto.js:3`

The file immediately invokes the exported function from './shim' at top-level (require-time). Since './shim' is not shown, this shim module can execute arbitrary code upon loading, including installing hooks, monkey-patching globals, harvesting environment variables/credentials, or performing network requests. Top-level execution on import is a common vector for malicious npm packages.

### [medium] Potential global environment modification

Finding ID: `NPS-D82F03A40BD5`

File: `auto.js:3`

The term 'shim' typically implies modifying global objects or built-ins (e.g. patching process, console, require, or other prototypes). Such behavior can silently alter runtime semantics for the entire application, enabling interception of sensitive data or stealthy execution.

### [medium] Opaque dependency

Finding ID: `NPS-31409DFFBCB2`

File: `auto.js:3`

The actual behavior cannot be verified from this file alone — all logic resides in './shim'. The entry point provides no indication of what the shim does, which is a common obfuscation/encapsulation pattern in malicious packages.

## Files reviewed

- `auto.js` (medium): The file is a thin wrapper that immediately executes an unspecified shim module at require-time, which is a potential vector for hidden malicious behavior such as credential harvesting, monkey-patching, or code execution, though no direct malicious code is visible.
- `implementation.js` (safe): This is a legitimate ES-shim polyfill implementation for String.prototype.matchAll with no malicious patterns detected.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `polyfill-regexp-matchall.js` (safe): Cleared by Jev triage; no further analysis needed
- `polyfill.js` (safe): No malicious activity detected; the code is a standard polyfill for String.prototype.matchAll that performs feature detection and wraps native implementations without any data exfiltration, credential harvesting, obfuscation, network access, or filesystem manipulation.
- `regexp-matchall.js` (safe): Cleared by Jev triage; no further analysis needed
- `shim.js` (safe): This is a legitimate polyfill shim for String.prototype.matchAll and Symbol.matchAll that only modifies built-in prototypes and does not exhibit any malicious patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
