Summary
Togoder Security scanned the npm package typescript@6.0.3 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
Process Spawning and Shell Command Execution
NPS-0A770B22ECBB
The code uses child_process.execSync to execute npm install commands. While this appears to be legitimate TypeScript typings installer functionality, executing shell commands based on npm package names and paths could potentially be exploited if inputs are not properly sanitized.
Dynamic code execution via global object
NPS-BF3542914DCA
The code checks for global.gc and calls it via global.gc call. This is a standard Node.js feature (--expose-gc) and not inherently malicious, but it references global object properties.
File system manipulation outside package scope
NPS-34BD5A55B15C
The code logs to files and can read/create directories in user home/cache locations (e.g., LOCALAPPDATA, XDG_CACHE_HOME). This is expected TypeScript tsserver behavior for logging and caching typing information.
Spawning processes or shell commands
NPS-35C04EEAFE8C
The code uses child_process.fork to spawn a typings installer process (typingsInstaller.js). This is a standard TypeScript feature for downloading type definitions, but it involves executing a child process.
Spawning processes or shell commands
NPS-2702692DF766
The code uses child_process.execFileSync to launch an external script (watchGuard.js) via the Node.js executable. This is a legitimate TypeScript tsserver feature for Windows directory watching, but process spawning capabilities require scrutiny.
Array Indexing Error
NPS-68447948CA4D
On line 159 within the indent function, there's a bug where str.replace(/ ? /, ...) lacks the global flag 'g', so it only replaces the first newline occurrence instead of all occurrences. This is a code quality issue rather than a security vulnerability.
File system access
NPS-41E90572B1A2
The script uses fs.watch with recursive option on a directory provided via process.argv[2]. This is a legitimate pattern used by TypeScript's watchGuard to test whether recursive file watching is supported. It closes the watcher immediately and exits, with no data exfiltration, credential harvesting, or external network activity.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/_tsserver.js | medium | The file is a legitimate TypeScript tsserver component with expected child process spawning for watch guard and typings installer, but no clear malicious patterns were identified. |
| lib/_typingsInstaller.js | medium | This is a legitimate TypeScript typings installer file from Microsoft that spawns npm commands to install type definitions, with no evidence of malicious patterns like data exfiltration, credential harvesting, or obfuscated code. |
| lib/tsc.js | safe | The code is a benign shim that enables Node.js compile cache before loading the real module, with no malicious patterns detected. |
| lib/tsserver.js | safe | No malicious patterns detected |
| lib/tsserverlibrary.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/typingsInstaller.js | safe | The shim only enables Node's built-in compile cache and loads the locally scoped implementation file, with no malicious patterns detected. |
| lib/watchGuard.js | safe | This appears to be a legitimate TypeScript compiler helper (watchGuard.js) that tests recursive fs.watch support and contains no malicious patterns. |
Affected version ranges
None of the 3 scanned versions of typescript are flagged high or critical. The latest scanned version, 7.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 6.0.3 – 7.0.2 | Needs review | 2 | >=6.0.3 <=7.0.2 | Process Spawning and Shell Command Execution; Process Spawning |
| 6.0.2 | Not scanned | 1 | 6.0.2 | |
| 5.9.3 | Needs review | 1 | 5.9.3 | Process spawning; File system access |
| 5.5.4 – 5.9.2 | Not scanned | 7 | >=5.5.4 <=5.9.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of typescript
Frequently asked questions
Is typescript safe to use?
No confirmed malware was found in typescript@6.0.3, but the review flagged 1 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does typescript contain malware?
No malware was identified in typescript@6.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was typescript checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan typescript together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in typescript@6.0.3, cost nothing.