Summary
Togoder Security scanned the npm package tar@7.5.19 on Oct 6, 2026. An AI review of 60 source files produced 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
No malicious patterns present
NPS-7A34840727C0
This file is the standard 'tar' npm package Pack implementation. It does not contain network calls, child_process usage, eval/new Function, environment variable harvesting, credential file access, obfuscation, or install-time lifecycle code. Imports are limited to fs, path, minipass, minizlib, yallist, and local modules.
Filesystem traversal via cwd option
NPS-80D7E48F7DCE
The Pack class accepts a 'cwd' option (this.cwd = opt.cwd || process.cwd()) and resolves arbitrary user-supplied paths relative to it using path.resolve. If a consumer passes untrusted input as a path to add()/write(), it could read files outside the intended scope. While this is the intended behavior of a tar creation library, callers must sanitize paths. Not an inherent backdoor, but a usage caution.
Synchronous filesystem operations
NPS-8EFE61FB200E
PackSync performs synchronous fs.statSync/lstatSync/readdirSync operations. If invoked with attacker-controlled paths, this could be used for filesystem oracle attacks (e.g., timing or error-based enumeration of paths). Not malicious per se, but a potential attack surface if the library is exposed to untrusted input.
Path traversal protection
NPS-6DEC213E2355
The code implements extensive path sanitization including stripAbsolutePath, '..' detection, cwd containment checks, and symlink escape prevention (ENSURE_NO_SYMLINK) which are defensive security measures, not vulnerabilities.
Filesystem operations
NPS-7C02B5108708
Performs file/directory creation, unlinking, chmod, chown, symlink/hardlink creation, and utimes. All operations are confined to the configured cwd with path escape protections. This is expected behavior for a tar extraction library.
Windows-specific unlink workaround
NPS-13A8DD298434
Uses randomBytes(16) for temporary rename filenames on Windows to work around non-atomic unlink semantics. This is a legitimate documented workaround, not obfuscation.
file system manipulation
NPS-9F4F7D10FE02
The module manipulates the file system by creating directories, changing ownership, changing permissions, and unlinking files. These actions are part of the intended functionality of a mkdir wrapper used by the tar package and are constrained to the provided working directory and options.
symlink protection
NPS-3EEC9C4B738B
The code explicitly prevents directory traversal through symlinks when preservePaths is not set, by throwing SymlinkError. This is a security hardening measure, not a vulnerability.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/commonjs/pack.js | medium | No malicious patterns detected; the file is a legitimate tar stream packer, though callers should sanitize paths passed to add()/write() and be aware of synchronous filesystem access in PackSync. |
| dist/commonjs/create.js | safe | The code is a legitimate tarball creation module (node-tar) with no malicious patterns, network activity, credential harvesting, or obfuscation detected. |
| dist/commonjs/cwd-error.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/commonjs/extract.js | safe | No malicious patterns detected; the file is a standard TypeScript-compiled CommonJS module implementing tar extraction functionality with no suspicious behavior. |
| dist/commonjs/get-write-flag.js | safe | No malicious patterns detected |
| dist/commonjs/header.js | safe | No malicious patterns detected; the code is a standard tar header parser/encoder from node-tar with no external network, process, or credential access. |
| dist/commonjs/index.js | safe | No malicious patterns detected; this is standard TypeScript-generated CommonJS re-export boilerplate with no network, filesystem, or process activity. |
| dist/commonjs/large-numbers.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/commonjs/list.js | safe | The code implements a standard tar archive listing function using fs, path, and minipass libraries with no malicious patterns, external network calls, or credential harvesting. |
| dist/commonjs/make-command.js | safe | No malicious patterns detected; the code is a simple command factory with no network, file system, process execution, or obfuscation. |
| dist/commonjs/mkdir.js | safe | No malicious patterns detected; this is a legitimate tar package mkdir utility with expected filesystem operations. |
| dist/commonjs/mode-fix.js | safe | No malicious patterns detected; the code is a simple, pure function for normalizing file permission modes. |
| dist/commonjs/normalize-unicode.js | safe | The code implements a Unicode normalization cache with no network, filesystem, process, or dynamic code execution patterns; it is safe. |
| dist/commonjs/normalize-windows-path.js | safe | No malicious patterns detected |
| dist/commonjs/options.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/commonjs/parse.js | safe | No malicious patterns detected |
| dist/commonjs/path-reservations.js | safe | No malicious patterns detected |
| dist/commonjs/pax.js | safe | No malicious patterns detected; the code is a normal PAX tar header encoder/parser with only Node.js path and internal header imports. |
| dist/commonjs/process-umask.js | safe | No malicious patterns detected |
| dist/commonjs/read-entry.js | safe | No malicious patterns detected; the file contains legitimate tar entry parsing logic for a tar library. |
| dist/commonjs/replace.js | safe | The code implements legitimate tar archive replace functionality using standard Node.js file system operations and has no malicious patterns. |
| dist/commonjs/strip-absolute-path.js | safe | No malicious patterns detected; the code only strips absolute path prefixes using Node's built-in path module. |
| dist/commonjs/strip-trailing-slashes.js | safe | The file contains a simple, optimized string utility that strips trailing slashes and exhibits no malicious patterns or security concerns. |
| dist/commonjs/symlink-error.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/commonjs/types.js | safe | No malicious patterns detected; the code is a simple type mapping module for tar file entry types with no network, filesystem, process, or dynamic execution behavior. |
Show 35 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/commonjs/unpack.js | safe | This is the node-tar unpack module with legitimate tar extraction logic; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or shell execution were detected. |
| dist/commonjs/update.js | safe | No malicious patterns detected; the code is a standard tar update wrapper with mtime filtering. |
| dist/commonjs/warn-method.js | safe | This file contains a benign warning/error emitter utility with no malicious patterns such as data exfiltration, code execution, or file system manipulation. |
| dist/commonjs/winchars.js | safe | No malicious patterns detected |
| dist/commonjs/write-entry.js | safe | No malicious patterns detected; the code is a legitimate tar entry writer with no data exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/create.js | safe | No malicious patterns detected; the code performs legitimate tar archive creation with no security concerns. |
| dist/esm/cwd-error.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/extract.js | safe | This is a legitimate tar extraction implementation using standard Node.js file system and stream APIs, with no malicious patterns detected. |
| dist/esm/get-write-flag.js | safe | No malicious patterns detected; the code is a benign file-open flag helper with no network, credential, or execution activity. |
| dist/esm/header.js | safe | This is a legitimate tar header parsing implementation from the node-tar package with no malicious patterns, network activity, credential access, or code execution detected. |
| dist/esm/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/large-numbers.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/list.js | safe | No malicious patterns detected |
| dist/esm/make-command.js | safe | No malicious patterns detected |
| dist/esm/mkdir.js | safe | The code is a legitimate mkdir wrapper for the tar package with standard file system operations and symlink protection, and no malicious patterns were detected. |
| dist/esm/mode-fix.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/normalize-unicode.js | safe | No malicious patterns detected; the code only performs local Unicode normalization with an in-memory cache and does not access network, filesystem, environment variables, or spawn processes. |
| dist/esm/normalize-windows-path.js | safe | No malicious patterns detected |
| dist/esm/options.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/pack.js | safe | The code is a legitimate tar archive creation library (node-tar) with no malicious patterns such as data exfiltration, credential harvesting, or backdoor installation. |
| dist/esm/parse.js | safe | No malicious patterns detected; the code is a legitimate tar archive parser with standard decompression and event handling. |
| dist/esm/path-reservations.js | safe | The code implements a path reservation system for concurrent file operations and contains no malicious patterns, external network calls, credential harvesting, or dynamic code execution. |
| dist/esm/pax.js | safe | No malicious patterns detected |
| dist/esm/process-umask.js | safe | The file only exports a simple wrapper for process.umask() with no malicious patterns detected. |
| dist/esm/read-entry.js | safe | No malicious patterns detected; this is a standard tar entry parser handling paths and parsing headers. |
| dist/esm/replace.js | safe | No malicious patterns detected; the code implements tar archive replacement logic using standard Node.js file system operations without any exfiltration, credential harvesting, obfuscation, or command execution. |
| dist/esm/strip-absolute-path.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/strip-trailing-slashes.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/symlink-error.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/unpack.js | safe | No malicious patterns detected; the file is the legitimate node-tar unpack implementation with standard path sanitization and extraction safeguards. |
| dist/esm/update.js | safe | No malicious patterns detected; the code implements tar update functionality using standard imports and a mtime-based filter with no exfiltration, dynamic execution, or process spawning. |
| dist/esm/warn-method.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/winchars.js | safe | No malicious patterns detected |
| dist/esm/write-entry.js | safe | This is a legitimate tar entry writing module from the node-tar package that handles file system operations for creating tar archives without any malicious patterns. |
Affected version ranges
None of the 3 scanned versions of tar are flagged high or critical. The latest scanned version, 7.5.22, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 6.2.1 โ 7.5.22 | Needs review | 3 | >=6.2.1 <=7.5.22 | Preserve paths / path traversal risk; Symlink/hardlink creation |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of tar
Frequently asked questions
Is tar safe to use?
No confirmed malware was found in tar@7.5.19, but the review flagged 8 low severity findings for risky patterns worth checking before you rely on it.
Does tar contain malware?
No malware was identified in tar@7.5.19 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was tar checked?
Togoder Security downloaded the published npm package and had an AI model read its 60 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan tar together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in tar@7.5.19, cost nothing.