Summary
Togoder Security scanned the npm package typescript@5.9.3 on Oct 4, 2026. An AI review of 7 source files produced 4 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Process spawning
NPS-33D43681151D
The code uses import_child_process.default.execFileSync and import_child_process.default.fork to spawn processes. While this is expected for TypeScript server functionality (typings installer, watch guard), it still represents a dangerous capability that could be abused if the package were compromised.
File system access
NPS-7364C6298A48
The code reads and writes files using fs.openSync, fs.writeSync, fs.close, and fs.existsSync. It accesses log files, credentials/cache locations, and the file system for module resolution. This is standard for tsserver but could be leveraged for data exfiltration or tampering if malicious.
Child Process Execution
NPS-5FB15218C61E
The code uses child_process.execSync to run npm install commands. While this is legitimate TypeScript functionality for installing type definitions, it executes shell commands which could be a security concern if the npmPath or package names are attacker-controlled.
Dynamic Command Construction
NPS-90E037310CB6
The npm install command is constructed dynamically using this.npmPath, this.latestDistTag, and packageNames. If any of these values are influenced by external input, it could lead to command injection.
Network communication
NPS-2F906A50C977
The code connects to an event port via net.connect using a port supplied through command-line arguments (--eventPort). This is part of TypeScript's event system but could theoretically be abused to communicate with external services if the port argument were attacker-controlled.
Environment variable access
NPS-08905A3D6791
The code reads multiple environment variables (TSS_LOG, TSS_TRACE, LOCALAPPDATA, APPDATA, USERPROFILE, HOMEDRIVE, HOMEPATH, XDG_CACHE_HOME, HOME, LOGNAME, USER, etc.) for legitimate configuration and cache location purposes. No credential harvesting patterns were observed.
File System Operations
NPS-5CD4C2E3B08A
The code reads and writes files (log files, types registry) using fs.appendFileSync and fs.readFile. It also ensures directory existence and installs packages into a global cache location. This is expected for a typings installer but involves file system manipulation outside the immediate package scope.
Network Activity via npm
NPS-155CCE07C12D
The npm install command will make network requests to fetch packages from the npm registry. While this is the intended function, it relies on an external service and could be a vector for dependency confusion or malicious package installation if the registry is compromised.
Environment Variable and Argument Access
NPS-FE9162ED504B
The code accesses process.argv and command-line arguments (via typescript_exports.server.findArgument). This is normal for a Node.js script but could be used to pass malicious paths or configurations.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/_tsserver.js | medium | This appears to be the legitimate TypeScript tsserver implementation with expected process spawning, file system access, and networking capabilities; no clear malicious intent, but the powerful primitives warrant caution if the package source is untrusted. |
| lib/_typingsInstaller.js | medium | The file is part of the TypeScript compiler's typings installer, which legitimately spawns npm processes to install type definitions, but its use of dynamic command execution and file system operations warrants a warning-level risk assessment. |
| lib/tsc.js | safe | The code is a benign shim that enables Node.js compile cache before loading the real module, with no malicious patterns detected. |
| lib/tsserver.js | safe | No malicious patterns detected |
| lib/tsserverlibrary.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/typingsInstaller.js | safe | The shim only enables Node's built-in compile cache and loads the locally scoped implementation file, with no malicious patterns detected. |
| lib/watchGuard.js | safe | No malicious patterns detected |
Affected version ranges
None of the 3 scanned versions of typescript are flagged high or critical. The latest scanned version, 7.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 6.0.3 – 7.0.2 | Needs review | 2 | >=6.0.3 <=7.0.2 | Process Spawning and Shell Command Execution; Process Spawning |
| 6.0.2 | Not scanned | 1 | 6.0.2 | |
| 5.9.3 | Needs review | 1 | 5.9.3 | Process spawning; File system access |
| 5.5.4 – 5.9.2 | Not scanned | 7 | >=5.5.4 <=5.9.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of typescript
Frequently asked questions
Is typescript safe to use?
No confirmed malware was found in typescript@5.9.3, but the review flagged 4 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does typescript contain malware?
No malware was identified in typescript@5.9.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was typescript checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan typescript together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in typescript@5.9.3, cost nothing.