# tar-stream@2.2.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:41:07.000Z
- Files reviewed: 5
- Findings: 1 high, 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/tar-stream
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tar-stream@2.2.0 on Oct 4, 2026. An AI review of 5 source files produced 1 high, 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Path Traversal / Directory Traversal

Finding ID: `NPS-A0E3D594C0AA`

File: `sandbox.js:8`

The extracted tar entry name is joined directly to '/tmp' without validation. A malicious tar file could include entries with '../' sequences or absolute paths, allowing files to be written outside the intended /tmp directory.

### [medium] Unsafe Archive Extraction

Finding ID: `NPS-A7F71E259144`

File: `sandbox.js:6`

Using tar-stream's extract without validation of header metadata (e.g., checking header.type for 'file' vs 'directory' vs symlink, or sanitizing header.name) can lead to symlink attacks, overwriting of arbitrary files, or denial of service via malformed archives.

### [low] Dependency Typosquatting / Misleading Module

Finding ID: `NPS-862C6F159F62`

File: `sandbox.js:3`

The comment indicates the variable 'pipeline' is expected to be require('stream').pipeline, but the code requires the 'pump' package. While 'pump' is a legitimate stream utility, this mismatch could indicate confusion or dependency substitution. Not inherently malicious but reduces code clarity and trust.

## Files reviewed

- `sandbox.js` (medium): The code extracts tar archives without sanitizing entry paths, enabling path traversal and potential arbitrary file writes outside /tmp.
- `extract.js` (safe): This is a legitimate tar stream extractor with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
- `headers.js` (safe): No malicious patterns detected
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `pack.js` (safe): No malicious patterns detected; the code implements a standard tar archive packing utility without exfiltration, credential harvesting, dynamic execution, or suspicious system interactions.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
