# typescript@7.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T15:35:20.000Z
- Files reviewed: 111
- Findings: 8 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/typescript
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package typescript@7.0.2 on Oct 4, 2026. An AI review of 111 source files produced 8 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Process Spawning

Finding ID: `NPS-84AD934911B0`

File: `dist/api/async/client.js:50`

The client spawns a child process using node:child_process with a dynamic executable path resolved from options (resolveExePath(options)) and passes user-controlled options like cwd. While this is a legitimate JSON-RPC client pattern, spawning external processes based on configurable paths can be abused if the package options are attacker-controlled.

### [medium] External Command Execution via Resolved Path

Finding ID: `NPS-56E72416DBBD`

File: `dist/api/async/client.js:50`

resolveExePath(options) determines which executable is spawned. If the options object comes from untrusted input, an attacker could point to a malicious executable, leading to arbitrary code execution.

### [medium] Process spawning via subprocess executable

Finding ID: `NPS-3624E028E440`

File: `dist/api/sync/client.js:45`

The Client constructor resolves an executable path via resolveExePath(options) from user-supplied SpawnOptions and passes it with arguments to SyncRpcChannel, which spawns a child process. While this is an explicit design of the library for supporting sync FFI-style RPC (similar to @rollup/pluginutils swc/napi-rs clients), it is a high-privilege operation that executes arbitrary binaries. If the options object is attacker-controlled, this could lead to arbitrary command execution.

### [medium] Process spawning with user-supplied executable path

Finding ID: `NPS-5E96F9E94D96`

File: `dist/api/syncChannel.js:96`

The SyncRpcChannel constructor accepts an arbitrary `exe` argument and spawns it as a child process. While this is the documented purpose of this module (an IPC replacement for libsyncrpc), it gives the caller the ability to execute any binary on the system. There is no validation or allowlisting of the executable path or arguments.

### [medium] Synchronous child process communication

Finding ID: `NPS-3464759BD68B`

File: `dist/api/syncChannel.js:130`

The module spawns a persistent child process and communicates over pipes using blocking fs.readSync/writeSync operations. This is a high-privilege operation that could be abused if a caller passes a malicious executable path; the child process is auto-killed on parent exit, but runs with the parent's privileges in the interim.

### [medium] Dynamic import dependency

Finding ID: `NPS-77AEF9DD8267`

File: `lib/tsc.js:3`

The script imports from the hash subpath '#getExePath'. The actual resolution of this subpath is defined in the package.json 'imports' field, which is not available for review here. A malicious package could point this to an arbitrary local file, a remote module, or a binary path, making the behavior of this file unpredictable without inspecting package metadata.

### [medium] Process.execve usage

Finding ID: `NPS-E7C4BF614648`

File: `lib/tsc.js:13`

On non-Windows platforms with Node > v22.15.0, process.execve is called to replace the current process image with the resolved executable. This is a legitimate optimization pattern but has the same trust dependency on '#getExePath' and inherits the full environment, including secrets, to the spawned process.

### [medium] Process execution

Finding ID: `NPS-474A9B630C2E`

File: `lib/tsc.js:18`

The script uses child_process.execFileSync to execute a binary from getExePath at runtime. While the file does not itself contain exfiltration, credential harvesting, obfuscation, or mining logic, it is a process launcher whose security depends entirely on the imported '#getExePath' module, which is not shown. If that module is compromised or resolves to an attacker-controlled binary, arbitrary code execution would occur. The use of inherited stdio and argv passthrough also means user-supplied arguments are forwarded to the subprocess.

### [low] Dynamic Imports

Finding ID: `NPS-62AA801F1147`

File: `dist/api/async/client.js:38`

Uses dynamic import() for node:child_process and node:net. These are static module names and not user-controlled, so risk is low, but dynamic imports are a common obfuscation technique to evade static analysis.

### [low] Unix Domain Socket Connection

Finding ID: `NPS-00CB1EE8F709`

File: `dist/api/async/client.js:76`

connectViaSocket connects to a Unix domain socket path provided via options.pipe. If this path is user-controlled, it could allow connection to arbitrary local sockets, potentially interacting with other local services.

### [low] Environment/working directory influenced process execution

Finding ID: `NPS-7BA75D1A42F5`

File: `dist/api/sync/client.js:18`

The child process is launched with cwd derived from options.cwd (falling back to process.cwd()) and enabled callbacks are forwarded as command-line arguments. This means caller-supplied inputs directly influence the spawned process's environment and arguments.

### [low] Dynamic callback registration / JSON parsing of external input

Finding ID: `NPS-A268179F82F3`

File: `dist/api/sync/client.js:50`

Enabled FS callbacks are looked up dynamically by name from fsCallbackNames, registered on the channel, and invoke callback(JSON.parse(arg)). JSON.parse on untrusted input is generally safe in JS, but the pattern of forwarding user-supplied data through callbacks can be exploited if the callback implementations perform privileged operations.

### [low] Binary request/response RPC over external process

Finding ID: `NPS-09C1D7E78533`

File: `dist/api/sync/client.js:83`

apiRequestBinary and echoBinary transmit encoded payloads to the external process and return raw binary results, which could be used to smuggle data outside the package if the spawned binary is malicious or the channel is hijacked.

### [low] Raw file descriptor access via internal Node.js APIs

Finding ID: `NPS-B4DBDDF586E2`

File: `dist/api/syncChannel.js:117`

The code reaches into internal Node.js internals (`stdout._handle.fd`, `stdin._handle.fd`, `setBlocking`) to obtain and manipulate pipe file descriptors directly. This bypasses the public stream API and could behave unpredictably across Node.js versions; malformed or corrupted pipe data could still cause unexpected reads/writes.

## Files reviewed

- `dist/api/async/client.js` (medium): This is a legitimate TypeScript API client using JSON-RPC over STDIO/sockets, but it spawns child processes with configurable executable paths and connects to user-specified sockets, which could be abused if options are attacker-controlled.
- `dist/api/sync/client.js` (medium): The code is a legitimate sync RPC client that spawns a caller-specified helper binary and forwards FS callbacks; the main risk is that user-controlled options can cause arbitrary process execution, so it should only be used with trusted executable paths.
- `dist/api/syncChannel.js` (medium): This module spawns arbitrary child processes specified by the caller and communicates over pipes, but contains no exfiltration, credential harvesting, obfuscation, or backdoor behavior; risk is limited to its inherently powerful process-spawning API.
- `lib/tsc.js` (medium): No direct malicious patterns are present, but the script executes an external binary resolved via an unshown import alias, making its safety dependent on the unimplemented '#getExePath' module and package.json imports configuration.
- `dist/api/async/api.js` (safe): This is the public TypeScript-Go async API client library; it contains only IPC/RPC plumbing to a local TypeScript language server with no exfiltration, dynamic code execution, credential harvesting, or install-time behavior.
- `dist/api/async/types.js` (safe): No malicious patterns detected
- `dist/api/compilerOptions.js` (safe): No malicious patterns detected
- `dist/api/fs.js` (safe): No malicious patterns detected; the file implements a purely in-memory virtual filesystem with no network, process, environment, or dynamic code execution behavior.
- `dist/api/node/encoder.generated.js` (safe): No malicious patterns detected; the file is a generated TypeScript AST encoder with static logic and no network, filesystem, process, or dynamic code execution behavior.
- `dist/api/node/encoder.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api/node/msgpack.js` (safe): No malicious patterns detected; the code is a standard MessagePack encoder/decoder implementation with no network, filesystem, process, or dynamic execution activity.
- `dist/api/node/node.generated.js` (safe): This is auto-generated read-only AST node accessor code for a TypeScript tooling package with no network, filesystem, process execution, environment, or dynamic code evaluation behaviors.
- `dist/api/node/node.infrastructure.js` (safe): No malicious patterns detected
- `dist/api/node/node.js` (safe): No malicious patterns detected; this is a TypeScript compiler API binary AST decoder with no network, process, or filesystem activity.
- `dist/api/node/protocol.generated.js` (safe): No malicious patterns detected
- `dist/api/node/protocol.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api/node/wtf8.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api/options.js` (safe): No malicious patterns detected in this small utility module; it only resolves an executable path and checks spawn options structure.
- `dist/api/path.js` (safe): No malicious patterns detected; the file contains standard path/URI manipulation utilities with no network, process, filesystem, or dynamic code execution behaviors.
- `dist/api/proto.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api/sourceFileCache.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api/sync/api.js` (safe): This is an auto-generated TypeScript/JavaScript API client for the TypeScript native preview compiler; it contains no malicious patterns such as exfiltration, credential harvesting, dynamic execution, or process spawning.
- `dist/api/sync/types.js` (safe): No malicious patterns detected
- `dist/api/timing.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/ast.generated.js` (safe): No malicious patterns detected
- `dist/ast/ast.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/astnav.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/clone.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/index.js` (safe): No malicious patterns detected
- `dist/ast/is.generated.js` (safe): No malicious patterns detected; the file contains only auto-generated AST type-guard predicates with no side effects, network, filesystem, or process activity.
- `dist/ast/is.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/jsdoc.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/ast/visitor.generated.js` (safe): No malicious patterns detected; this is a generated TypeScript AST visitor module with only static imports and pure node-update logic.
- `dist/ast/visitor.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/enums/characterCodes.enum.js` (safe): This file only defines a static enum of character codes with no executable logic, network access, file system operations, or other malicious patterns.
- `dist/enums/characterCodes.js` (safe): No malicious patterns detected; the file only defines a TypeScript enum for character codes.
- `dist/enums/commentDirectiveType.enum.js` (safe): No malicious patterns detected
- `dist/enums/commentDirectiveType.js` (safe): No malicious patterns detected; the file only defines a TypeScript enum for comment directive types with no network, filesystem, process, or dynamic execution activity.
- `dist/enums/completionItemKind.enum.js` (safe): No malicious patterns detected
- `dist/enums/completionItemKind.js` (safe): No malicious patterns detected
- `dist/enums/diagnosticCategory.enum.js` (safe): No malicious patterns detected; the code is a simple compiled TypeScript enum with no runtime side effects, network activity, or file system access.
- `dist/enums/diagnosticCategory.js` (safe): No malicious patterns detected
- `dist/enums/elementFlags.enum.js` (safe): No malicious patterns detected; the file is a simple generated TypeScript enum with no executable, network, or filesystem behavior.
- `dist/enums/elementFlags.js` (safe): No malicious patterns detected
- `dist/enums/internalSymbolName.enum.js` (safe): No malicious patterns detected; the file is a simple auto-generated enum of internal symbol name constants with no executable or suspicious behavior.
- `dist/enums/internalSymbolName.js` (safe): No malicious patterns detected
- `dist/enums/jsxEmit.enum.js` (safe): No malicious patterns detected; the code is a simple generated TypeScript enum definition with no dynamic execution, network, filesystem, or process activity.
- `dist/enums/jsxEmit.js` (safe): No malicious patterns detected; the file only defines a TypeScript-compiled enum for JSX emit options with no executable, network, or filesystem behavior.
- `dist/enums/languageVariant.enum.js` (safe): No malicious patterns detected
- `dist/enums/languageVariant.js` (safe): No malicious patterns detected; the file only defines a simple TypeScript enum for LanguageVariant with no external I/O, dynamic execution, or network activity.
- `dist/enums/modifierFlags.enum.js` (safe): No malicious patterns detected
- `dist/enums/modifierFlags.js` (safe): No malicious patterns detected
- `dist/enums/moduleDetectionKind.enum.js` (safe): No malicious patterns detected
- `dist/enums/moduleDetectionKind.js` (safe): No malicious patterns detected; the file is a generated TypeScript enum definition with no executable or suspicious behavior.
- `dist/enums/moduleKind.enum.js` (safe): No malicious patterns detected; this is a standard generated TypeScript enum definition for ModuleKind.
- `dist/enums/moduleKind.js` (safe): No malicious patterns detected
- `dist/enums/moduleResolutionKind.enum.js` (safe): No malicious patterns detected
- `dist/enums/moduleResolutionKind.js` (safe): No malicious patterns detected; the file is a simple generated TypeScript enum definition with no executable or network-related behavior.
- `dist/enums/newLineKind.enum.js` (safe): No malicious patterns detected
- `dist/enums/newLineKind.js` (safe): No malicious patterns detected
- `dist/enums/nodeBuilderFlags.enum.js` (safe): No malicious patterns detected; the file is a generated TypeScript enum mapping with no network, filesystem, process, or dynamic code execution behavior.
- `dist/enums/nodeBuilderFlags.js` (safe): No malicious patterns detected; the file is a benign TypeScript-generated enum definition with no executable, network, filesystem, or process-related code.
- `dist/enums/nodeFlags.enum.js` (safe): No malicious patterns detected
- `dist/enums/nodeFlags.js` (safe): No malicious patterns detected; the file only defines a TypeScript/JavaScript enum for AST node flags with no executable, network, or filesystem behavior.
- `dist/enums/objectFlags.enum.js` (safe): No malicious patterns detected
- `dist/enums/objectFlags.js` (safe): No malicious patterns detected
- `dist/enums/outerExpressionKinds.enum.js` (safe): No malicious patterns detected
- `dist/enums/outerExpressionKinds.js` (safe): This file is an auto-generated TypeScript/JavaScript enum definition for AST outer expression kinds with no executable logic, network calls, file system access, or other malicious patterns.
- `dist/enums/regularExpressionFlags.enum.js` (safe): The file contains only a legitimate TypeScript-compiled enum definition for regular expression flags with no malicious patterns, network activity, file system access, or dynamic code execution.
- `dist/enums/regularExpressionFlags.js` (safe): No malicious patterns detected; the file defines a simple TypeScript enum for regular expression flags with no suspicious behavior.
- `dist/enums/scriptKind.enum.js` (safe): No malicious patterns detected
- `dist/enums/scriptKind.js` (safe): No malicious patterns detected
- `dist/enums/scriptTarget.enum.js` (safe): No malicious patterns detected
- `dist/enums/scriptTarget.js` (safe): No malicious patterns detected
- `dist/enums/signatureFlags.enum.js` (safe): No malicious patterns detected
- `dist/enums/signatureFlags.js` (safe): No malicious patterns detected; the file only defines a TypeScript enums mapping with no network, filesystem, process, or dynamic code execution behavior.
- `dist/enums/signatureKind.enum.js` (safe): No malicious patterns detected in this auto-generated TypeScript enum definition file.
- `dist/enums/signatureKind.js` (safe): No malicious patterns detected
- `dist/enums/symbolFlags.enum.js` (safe): No malicious patterns detected
- `dist/enums/symbolFlags.js` (safe): No malicious patterns detected
- `dist/enums/syntaxKind.enum.js` (safe): No malicious patterns detected
- `dist/enums/syntaxKind.js` (safe): No malicious patterns detected
- `dist/enums/tokenFlags.enum.js` (safe): No malicious patterns detected
- `dist/enums/tokenFlags.js` (safe): No malicious patterns detected
- `dist/enums/typeFlags.enum.js` (safe): No malicious patterns detected; this is a generated TypeScript enum definition file with no executable behavior beyond simple enum initialization.
- `dist/enums/typeFlags.js` (safe): No malicious patterns detected; file is a generated TypeScript enum definition with no executable, network, or filesystem behavior.
- `dist/enums/typePredicateKind.enum.js` (safe): This file contains only a generated TypeScript enum definition with no executable logic, network activity, file system access, or other malicious patterns.
- `dist/enums/typePredicateKind.js` (safe): No malicious patterns detected
- `dist/internal/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/getExePath.js` (safe): No malicious patterns detected; the code only resolves a platform-specific executable path from package metadata and performs expected filesystem checks.
- `lib/version.cjs` (safe): No malicious patterns detected
- `vendor/vscode-jsonrpc/lib/browser/main.js` (safe): No malicious patterns detected; the code is a legitimate Microsoft vscode-jsonrpc browser module implementing message reader/writer for web worker ports.
- `vendor/vscode-jsonrpc/lib/browser/ril.js` (safe): No malicious patterns detected
- `vendor/vscode-jsonrpc/lib/common/api.js` (safe): No malicious patterns detected; this is a standard re-export barrel file for the vscode-jsonrpc library.
- `vendor/vscode-jsonrpc/lib/common/cancellation.js` (safe): No malicious patterns detected; this is a legitimate Microsoft vscode-jsonrpc cancellation token utility module with standard TypeScript transpilation helpers and no suspicious behavior.
- `vendor/vscode-jsonrpc/lib/common/connection.js` (safe): This is the official Microsoft vscode-jsonrpc connection implementation with standard JSON-RPC message handling, no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or suspicious execution detected.
- `vendor/vscode-jsonrpc/lib/common/disposable.js` (safe): Cleared by Jev triage; no further analysis needed
- `vendor/vscode-jsonrpc/lib/common/encoding.js` (safe): Cleared by Jev triage; no further analysis needed
- `vendor/vscode-jsonrpc/lib/common/events.js` (safe): No malicious patterns detected
- `vendor/vscode-jsonrpc/lib/common/is.js` (safe): Cleared by Jev triage; no further analysis needed
- `vendor/vscode-jsonrpc/lib/common/linkedMap.js` (safe): Cleared by Jev triage; no further analysis needed
- `vendor/vscode-jsonrpc/lib/common/messageBuffer.js` (safe): Cleared by Jev triage; no further analysis needed
- `vendor/vscode-jsonrpc/lib/common/messageReader.js` (safe): No malicious patterns detected; the code is a standard VSCode JSON-RPC message reader implementation with no exfiltration, obfuscation, or suspicious behavior.
- `vendor/vscode-jsonrpc/lib/common/messageWriter.js` (safe): No malicious patterns detected in the reviewed file; it is a legitimate Microsoft vscode-jsonrpc message writer implementation using standard module helpers and RAL abstractions.
- `vendor/vscode-jsonrpc/lib/common/messages.js` (safe): No malicious patterns detected in the provided vscode-jsonrpc messages.js file; it contains only legitimate TypeScript/JavaScript message type definitions and helper functions.
- `vendor/vscode-jsonrpc/lib/common/ral.js` (safe): No malicious patterns detected; the file only implements a simple runtime abstraction layer registry with no network, filesystem, process, or dynamic code execution behavior.
- `vendor/vscode-jsonrpc/lib/common/semaphore.js` (safe): No malicious patterns detected; the code implements a standard semaphore with no network, filesystem, process, or dynamic code execution concerns.
- `vendor/vscode-jsonrpc/lib/common/sharedArrayCancellation.js` (safe): Cleared by Jev triage; no further analysis needed
- `vendor/vscode-jsonrpc/lib/node/main.js` (safe): No malicious patterns detected in this legitimate Microsoft vscode-jsonrpc Node.js IPC/socket transport module.
- `vendor/vscode-jsonrpc/lib/node/ril.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of typescript are flagged high or critical. The latest scanned version, 7.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 6.0.3 – 7.0.2 (`>=6.0.3 <=7.0.2`): medium (Process Spawning and Shell Command Execution +4 more)
- 6.0.2 (`6.0.2`): not scanned
- 5.9.3 (`5.9.3`): medium (Process spawning +3 more)
- 5.5.4 – 5.9.2 (`>=5.5.4 <=5.9.2`): not scanned

## Scanned versions

- [7.0.2](https://security.togoder.click/npm/typescript@7.0.2): medium, 2026-10-04T15:35:20.000Z
- [6.0.3](https://security.togoder.click/npm/typescript@6.0.3): medium, 2026-10-06T14:24:45.000Z
- [5.9.3](https://security.togoder.click/npm/typescript@5.9.3): medium, 2026-10-04T16:41:46.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
