Togoder security

npm package security report

typescript@5.9.3 security report

Risky patterns found that deserve a look.

Needs review Version 5.9.3 Files reviewed 7 Size 41.4 KB Scanned

Summary

Togoder Security scanned the npm package typescript@5.9.3 on Oct 4, 2026. An AI review of 7 source files produced 4 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
5
low

Findings 9

medium

Process spawning

NPS-33D43681151D

The code uses import_child_process.default.execFileSync and import_child_process.default.fork to spawn processes. While this is expected for TypeScript server functionality (typings installer, watch guard), it still represents a dangerous capability that could be abused if the package were compromised.

lib/_tsserver.js
medium

File system access

NPS-7364C6298A48

The code reads and writes files using fs.openSync, fs.writeSync, fs.close, and fs.existsSync. It accesses log files, credentials/cache locations, and the file system for module resolution. This is standard for tsserver but could be leveraged for data exfiltration or tampering if malicious.

lib/_tsserver.js
medium

Child Process Execution

NPS-5FB15218C61E

The code uses child_process.execSync to run npm install commands. While this is legitimate TypeScript functionality for installing type definitions, it executes shell commands which could be a security concern if the npmPath or package names are attacker-controlled.

lib/_typingsInstaller.js:126
medium

Dynamic Command Construction

NPS-90E037310CB6

The npm install command is constructed dynamically using this.npmPath, this.latestDistTag, and packageNames. If any of these values are influenced by external input, it could lead to command injection.

lib/_typingsInstaller.js:126
low

Network communication

NPS-2F906A50C977

The code connects to an event port via net.connect using a port supplied through command-line arguments (--eventPort). This is part of TypeScript's event system but could theoretically be abused to communicate with external services if the port argument were attacker-controlled.

lib/_tsserver.js
low

Environment variable access

NPS-08905A3D6791

The code reads multiple environment variables (TSS_LOG, TSS_TRACE, LOCALAPPDATA, APPDATA, USERPROFILE, HOMEDRIVE, HOMEPATH, XDG_CACHE_HOME, HOME, LOGNAME, USER, etc.) for legitimate configuration and cache location purposes. No credential harvesting patterns were observed.

lib/_tsserver.js
low

File System Operations

NPS-5CD4C2E3B08A

The code reads and writes files (log files, types registry) using fs.appendFileSync and fs.readFile. It also ensures directory existence and installs packages into a global cache location. This is expected for a typings installer but involves file system manipulation outside the immediate package scope.

lib/_typingsInstaller.js:60
low

Network Activity via npm

NPS-155CCE07C12D

The npm install command will make network requests to fetch packages from the npm registry. While this is the intended function, it relies on an external service and could be a vector for dependency confusion or malicious package installation if the registry is compromised.

lib/_typingsInstaller.js:126
low

Environment Variable and Argument Access

NPS-FE9162ED504B

The code accesses process.argv and command-line arguments (via typescript_exports.server.findArgument). This is normal for a Node.js script but could be used to pass malicious paths or configurations.

lib/_typingsInstaller.js:154

Files reviewed

FileVerdictWhat the reviewer saw
lib/_tsserver.js medium This appears to be the legitimate TypeScript tsserver implementation with expected process spawning, file system access, and networking capabilities; no clear malicious intent, but the powerful primitives warrant caution if the package source is untrusted.
lib/_typingsInstaller.js medium The file is part of the TypeScript compiler's typings installer, which legitimately spawns npm processes to install type definitions, but its use of dynamic command execution and file system operations warrants a warning-level risk assessment.
lib/tsc.js safe The code is a benign shim that enables Node.js compile cache before loading the real module, with no malicious patterns detected.
lib/tsserver.js safe No malicious patterns detected
lib/tsserverlibrary.js safe Cleared by Jev triage; no further analysis needed
lib/typingsInstaller.js safe The shim only enables Node's built-in compile cache and loads the locally scoped implementation file, with no malicious patterns detected.
lib/watchGuard.js safe No malicious patterns detected

Affected version ranges

None of the 3 scanned versions of typescript are flagged high or critical. The latest scanned version, 7.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.5.47.0.2
VersionsVerdictCountRangeTop findings
6.0.3 – 7.0.2 Needs review 2 >=6.0.3 <=7.0.2 Process Spawning and Shell Command Execution; Process Spawning
6.0.2 Not scanned 1 6.0.2
5.9.3 Needs review 1 5.9.3 Process spawning; File system access
5.5.4 – 5.9.2 Not scanned 7 >=5.5.4 <=5.9.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of typescript

VersionVerdictFilesScanned
7.0.2 Needs review 111 Oct 4, 2026
6.0.3 Needs review 7 Oct 6, 2026
5.9.3 Needs review 7 Oct 4, 2026

Frequently asked questions

Is typescript safe to use?

No confirmed malware was found in typescript@5.9.3, but the review flagged 4 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does typescript contain malware?

No malware was identified in typescript@5.9.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was typescript checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan typescript together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in typescript@5.9.3, cost nothing.

Related security reports