Summary
Togoder Security scanned the npm package tinyglobby@0.2.17 on Oct 6, 2026. An AI review of 2 source files produced 6 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 6
filesystem traversal
NPS-AC990BC28E52
The package uses fdir to crawl the filesystem based on glob patterns. While this is expected behavior for a globbing library, it does not appear to escape the provided working directory or access sensitive files beyond user-specified patterns.
symbolic link following
NPS-9B288420F744
The default option followSymbolicLinks is true, which could potentially follow symlinks outside the intended directory. However, this is a documented feature of the library and not inherently malicious.
command execution
NPS-D9F37ED6C712
No spawning of processes or shell commands was detected.
data exfiltration
NPS-A560CE530CF2
No network requests or data exfiltration patterns were found.
environment variable harvesting
NPS-95A362DCFD5C
Only TINYGLOBBY_DEBUG is read for debug logging; no sensitive environment variables are collected or transmitted.
obfuscation
NPS-900E60020A20
No obfuscated code or dynamic code execution (eval, Function, etc.) was observed.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs | safe | No malicious patterns detected; this is the legitimate tinyglobby file-globbing library with standard Node.js fs/path usage and no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/index.mjs | safe | The code appears to be a legitimate globbing library with no malicious patterns detected. |
Frequently asked questions
Is tinyglobby safe to use?
Our AI source review of tinyglobby@0.2.17 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does tinyglobby contain malware?
No malware was identified in tinyglobby@0.2.17 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was tinyglobby checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan tinyglobby together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in tinyglobby@0.2.17, cost nothing.