Togoder security

npm package security report

tinyexec@1.3.0 security report

Risky patterns found that deserve a look.

Needs review Version 1.3.0 Files reviewed 1 Size 12.3 KB Scanned

Summary

Togoder Security scanned the npm package tinyexec@1.3.0 on Oct 6, 2026. An AI review of 1 source file produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
2
low

Findings 4

medium

Process Spawning

NPS-1C791858DD1B

The module is a cross-platform process execution library that wraps child_process.spawn/spawnSync. It intentionally spawns arbitrary commands and shell processes (cmd.exe on Windows) based on caller input. While this is the package's stated purpose, it exposes a powerful API surface that can be abused by callers to execute arbitrary system commands.

dist/main.mjs:1
medium

Shell Command Construction

NPS-D0AB814613A6

On Windows, normalizeSpawnCommand constructs a cmd.exe invocation string by joining command and arguments with spaces and escaping meta characters. Bugs or bypasses in this escaping could lead to command injection if untrusted input is passed to exec/execSync.

dist/main.mjs:86
low

Environment Variable Manipulation

NPS-F25E5ED224FE

computeEnv reads and modifies the process environment, including injecting node_modules/.bin paths and the Node executable directory into PATH. This could cause unintended binaries to be resolved/executed if the working directory contains a malicious node_modules/.bin.

dist/main.mjs:32
low

Dynamic Command Resolution

NPS-A9F356191771

resolveCommand resolves the target command by traversing PATH and PATHEXT and reading files (statSync, openSync, readSync) to detect shebangs. This enables execution of resolved binaries and can be influenced by attacker-controlled environment or working directory.

dist/main.mjs:108

Files reviewed

FileVerdictWhat the reviewer saw
dist/main.mjs medium This is a legitimate cross-platform process execution library (similar to execa) that spawns arbitrary child processes and constructs shell commands; no direct malicious behavior (exfiltration, credential theft, obfuscation, backdoors) is present, but its command-execution capabilities warrant caution when used with untrusted input.

Frequently asked questions

Is tinyexec safe to use?

No confirmed malware was found in tinyexec@1.3.0, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does tinyexec contain malware?

No malware was identified in tinyexec@1.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was tinyexec checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan tinyexec together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in tinyexec@1.3.0, cost nothing.

Related security reports