# tar-fs@2.1.4 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:41:04.000Z
- Files reviewed: 1
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/tar-fs
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tar-fs@2.1.4 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [medium] Filesystem chmod/chown on extraction

Finding ID: `NPS-FA7F13B90D92`

File: `index.js`

The extract function can chmod/chown extracted files based on tar header uid/gid/mode. When run as root with untrusted archives, this could set unexpected permissions. This is expected behavior for tar extraction but should be noted.

### [low] Path traversal protection

Finding ID: `NPS-4CFA0830E729`

File: `index.js`

The code includes inCwd() and validate() functions to prevent extraction outside the target directory, mitigating zip-slip style attacks.

### [low] Symlink/hardlink validation

Finding ID: `NPS-766AB3204591`

File: `index.js`

Symlink and hardlink extraction paths are validated against the cwd, preventing link-based escapes.

### [low] Privilege escalation guard

Finding ID: `NPS-75144F266FA6`

File: `index.js`

chown operations only run when process.getuid() === 0 and opts.chown !== false, limiting unintended ownership changes.

## Files reviewed

- `index.js` (safe): The code is a legitimate tar packing/extraction library (node-tar) with standard path traversal protections; no malicious patterns such as exfiltration, credential harvesting, eval, or process spawning were detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
