Summary
Togoder Security scanned the npm package tinyexec@1.3.0 on Oct 6, 2026. An AI review of 1 source file produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Process Spawning
NPS-1C791858DD1B
The module is a cross-platform process execution library that wraps child_process.spawn/spawnSync. It intentionally spawns arbitrary commands and shell processes (cmd.exe on Windows) based on caller input. While this is the package's stated purpose, it exposes a powerful API surface that can be abused by callers to execute arbitrary system commands.
Shell Command Construction
NPS-D0AB814613A6
On Windows, normalizeSpawnCommand constructs a cmd.exe invocation string by joining command and arguments with spaces and escaping meta characters. Bugs or bypasses in this escaping could lead to command injection if untrusted input is passed to exec/execSync.
Environment Variable Manipulation
NPS-F25E5ED224FE
computeEnv reads and modifies the process environment, including injecting node_modules/.bin paths and the Node executable directory into PATH. This could cause unintended binaries to be resolved/executed if the working directory contains a malicious node_modules/.bin.
Dynamic Command Resolution
NPS-A9F356191771
resolveCommand resolves the target command by traversing PATH and PATHEXT and reading files (statSync, openSync, readSync) to detect shebangs. This enables execution of resolved binaries and can be influenced by attacker-controlled environment or working directory.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/main.mjs | medium | This is a legitimate cross-platform process execution library (similar to execa) that spawns arbitrary child processes and constructs shell commands; no direct malicious behavior (exfiltration, credential theft, obfuscation, backdoors) is present, but its command-execution capabilities warrant caution when used with untrusted input. |
Scanned versions of tinyexec
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.3.0 | Needs review | 1 | Oct 6, 2026 |
Frequently asked questions
Is tinyexec safe to use?
No confirmed malware was found in tinyexec@1.3.0, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does tinyexec contain malware?
No malware was identified in tinyexec@1.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was tinyexec checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan tinyexec together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in tinyexec@1.3.0, cost nothing.