Togoder security

npm package security report

tinyglobby npm package: is it safe?

No malicious code found.

No issues Version 0.2.17 Files reviewed 2 Size 25.5 KB Scanned

Summary

Togoder Security scanned the npm package tinyglobby@0.2.17 on Oct 6, 2026. An AI review of 2 source files produced 6 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
6
low

Findings 6

low

filesystem traversal

NPS-AC990BC28E52

The package uses fdir to crawl the filesystem based on glob patterns. While this is expected behavior for a globbing library, it does not appear to escape the provided working directory or access sensitive files beyond user-specified patterns.

dist/index.mjs
low

symbolic link following

NPS-9B288420F744

The default option followSymbolicLinks is true, which could potentially follow symlinks outside the intended directory. However, this is a documented feature of the library and not inherently malicious.

dist/index.mjs
low

command execution

NPS-D9F37ED6C712

No spawning of processes or shell commands was detected.

dist/index.mjs
low

data exfiltration

NPS-A560CE530CF2

No network requests or data exfiltration patterns were found.

dist/index.mjs
low

environment variable harvesting

NPS-95A362DCFD5C

Only TINYGLOBBY_DEBUG is read for debug logging; no sensitive environment variables are collected or transmitted.

dist/index.mjs
low

obfuscation

NPS-900E60020A20

No obfuscated code or dynamic code execution (eval, Function, etc.) was observed.

dist/index.mjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs safe No malicious patterns detected; this is the legitimate tinyglobby file-globbing library with standard Node.js fs/path usage and no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/index.mjs safe The code appears to be a legitimate globbing library with no malicious patterns detected.

Scanned versions of tinyglobby

VersionVerdictFilesScanned
0.2.17 No issues 2 Oct 6, 2026

Frequently asked questions

Is tinyglobby safe to use?

Our AI source review of tinyglobby@0.2.17 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does tinyglobby contain malware?

No malware was identified in tinyglobby@0.2.17 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was tinyglobby checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan tinyglobby together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in tinyglobby@0.2.17, cost nothing.

Related security reports