Summary
Togoder Security scanned the npm package tar@6.2.1 on Oct 4, 2026. An AI review of 26 source files produced 2 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Preserve paths / path traversal risk
NPS-9AA8057169C3
The preservePaths option (opt.preservePaths) disables protection against '..' and absolute path entries. When enabled, archives can write files outside the extraction target, enabling arbitrary file write. This is intentional but dangerous if exposed to untrusted archives.
Symlink/hardlink creation
NPS-BBD49C631BCD
The code creates symlinks and hardlinks based on archive-controlled linkpath values (entry.linkpath). Hardlinks are resolved relative to cwd and symlinks can point anywhere. Combined with path reservation and cache pruning logic, this is a known attack surface for tar extraction (link-based overwrite attacks).
Environment variable manipulation
NPS-3F53EBC16FA3
The code reads process.env.__FAKE_PLATFORM__ and global.__FAKE_TESTING_FS__, which allows overriding the platform detection and the fs module. While intended for testing, an attacker could potentially set these globals in a supply-chain attack to alter behavior (e.g., force the use of a malicious fs implementation).
Dynamic module loading via global injection
NPS-8C7AE96726C1
The code uses global.__FAKE_TESTING_FS__ to optionally replace the built-in fs module. If an attacker can inject this global (e.g., via another package or prototype pollution), they could supply a malicious fs object that intercepts file operations. This is a testing hook but introduces a potential bypass of normal module resolution.
File System Manipulation
NPS-C2E2E0AA6423
The code performs recursive directory creation and can optionally chown/chmod/unlink files. This is expected behavior for a mkdir wrapper, not malicious.
potential_input_validation_issue
NPS-985C9CF3FFA4
The parseKVLine function uses parseInt and Buffer.byteLength in a naive line-by-line parser, which may not robustly handle all PAX header inputs, but this is a functional limitation, not a malicious pattern.
File system manipulation outside package scope
NPS-BF24D5BADF44
The unpacker writes, chmods, chowns, unlinks, and creates directories anywhere under the configured cwd (or absolute paths if preservePaths is set). This is the intended function of a tar extractor, but it is a powerful operation that must be sandboxed by callers.
Suspicious environment variable usage
NPS-874D00198CCD
The code reads process.env.TESTING_TAR_FAKE_PLATFORM to override the platform detection. While this is documented as a testing aid, environment variable-controlled platform switching can be abused in some contexts to alter path handling behavior.
Privilege-related behavior (chown)
NPS-474360BA2E22
The code conditionally calls fs.chown/fchown based on preserveOwner (defaults true when running as root) or explicit uid/gid. If run as root with an untrusted archive, this could allow ownership changes on extracted files.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/get-write-flag.js | medium | The code contains test hooks that allow overriding platform and fs module via environment variables and globals, which could be abused in a supply-chain attack, but no direct malicious behavior is present. |
| lib/unpack.js | medium | This appears to be the legitimate node-tar unpacking library; no clear malicious patterns (exfiltration, backdoors, shell execution, obfuscation) were found, though it contains inherently powerful filesystem operations and path-preservation options that warrant care when used with untrusted archives. |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/create.js | safe | No malicious patterns detected; the code is a standard tar creation utility with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| lib/extract.js | safe | No malicious patterns detected |
| lib/header.js | safe | No malicious patterns detected; the code is a standard tar header encoder/decoder with no network, filesystem, or process manipulation. |
| lib/high-level-opt.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/large-numbers.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/list.js | safe | No malicious patterns detected; the code is part of the tar package's list functionality and performs expected file listing without any exfiltration, obfuscation, or process spawning. |
| lib/mkdir.js | safe | No malicious patterns detected; code is a standard mkdirp wrapper for tar extraction with expected filesystem operations. |
| lib/mode-fix.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/normalize-unicode.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/normalize-windows-path.js | safe | No malicious patterns detected |
| lib/pack.js | safe | The code is a legitimate tar stream creation library with no malicious patterns detected. |
| lib/parse.js | safe | No malicious patterns detected; this is a standard tar parser implementation with expected dependencies and no exfiltration, credential harvesting, obfuscation, or process execution. |
| lib/path-reservations.js | safe | No malicious patterns detected; this is a legitimate path reservation system for an archive unpacking library with no network, filesystem, or process activity. |
| lib/pax.js | safe | No malicious patterns detected; the code implements PAX tar extended header encoding/decoding without network, credential, process, or filesystem abuse. |
| lib/read-entry.js | safe | No malicious patterns detected; the code is a standard tar entry parser with no network, filesystem, or process execution risks. |
| lib/replace.js | safe | No malicious patterns detected |
| lib/strip-absolute-path.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/strip-trailing-slashes.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/types.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/update.js | safe | No malicious patterns detected; the code is a standard tar update module with expected option validation and filtering logic. |
| lib/warn-mixin.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/winchars.js | safe | Cleared by Jev triage; no further analysis needed |
Show 1 more file
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/write-entry.js | safe | No malicious patterns detected; code is a legitimate tar entry writer implementation with standard file system and stream operations. |
Affected version ranges
None of the 3 scanned versions of tar are flagged high or critical. The latest scanned version, 7.5.22, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 6.2.1 โ 7.5.22 | Needs review | 3 | >=6.2.1 <=7.5.22 | Preserve paths / path traversal risk; Symlink/hardlink creation |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of tar
Frequently asked questions
Is tar safe to use?
No confirmed malware was found in tar@6.2.1, but the review flagged 2 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does tar contain malware?
No malware was identified in tar@6.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was tar checked?
Togoder Security downloaded the published npm package and had an AI model read its 26 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan tar together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in tar@6.2.1, cost nothing.